cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
686
Views
0
Helpful
6
Replies

How to blockade MSN Web Messenger

ryan-wang
Level 1
Level 1

How to use PIX 7.0 to blockade MSN Web Messenger?

Thanks.

6 Replies 6

mchin345
Level 6
Level 6

The first thing we need to know is what ports are being used by MSN Messenger.you need to block TCP Ports 6891 to 6900 on the firewall.

Hi

there is more ports than that!

Here is what MS Engineer sent me:

These are the ports you need to block for the file transfer feature:

- MSN Messenger version 5 uses ports 6891 through 6900.

- MSN Messenger versions 6.2, 7.0, and 7.5 use TCP ports 6720 through 65535 or UDP ports 31000 through 31500.

Note: MSN Messenger chooses the appropriate range of ports based on the MSN Messenger version and the type of connection. If a direct connection is not possible, MSN Messenger transfers the file at a rate of 120 packets per minute, with each packet limited to 1300 bytes, through the switchboard server. MSN Messenger also uses the switchboard server for instant messaging.

These are the Internet ports that MSN Messenger for Windows uses.

Sign in to the MSN Messenger service:

- Port 1863 or the HTTP port

Note: The HTTP port is typically port 80.

Audio and video conferencing:

- UDP ports 5004 through 65535

Webcam and video conversations:

- MSN Messenger will try to connect on ports 80 or 8080. If those ports do not work, Messenger will try to connect on TCP ports 5000 through 65535. If those ports do not work, MSN Messenger will transmit webcam and video conversations through a reflector server on ports 9000 or 9001.

Whiteboard:

- Port 1503

Application sharing:

- Port 1503

Remote assistance:

- Port 3389

MSN Messenger can user port 80...

you will need to block the domain for MSN servers...

I tried to block MSN File transfert and this is IMPOSSIBLE! (Cisco engineer confirmed that fact)

reason: file transfert are not done directly. You pass the transaction to a MSN server and then the other PC

Hope it helps!

It is a bit difficult to block this stuff at the firewall, but if you have a ciso router, then all is good. You should check out nbar. It is awesome. It is very flexible. It also solves the p2p file sharing issues...

http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122newft/122t/122t8/dtnbarad.htm#90179

Thanks.

do u have ISA server behind ur firewall ? i tried everything with my Cisco firewall.. but was more cumbersome.. found easy doc for ISA. works perfect.

let me know and will drop in the URL .. setttings have to do with TCP header in ISA.

I hope Cisco simplifies Messenger blocking and issues documentation too ASAP. dont like goin to MS for security...

I saw your reply and can you provide the URL on how to do it using ISA.

Thanks