01-21-2016 05:39 PM
May we please ask your assistance regarding blocking of an application that bypasses our Ironport web security appliance. The application is an executable file. This is now widely used by proxy users and they can surf without restrictions. No logs found in Ironport web security appliance.
Solved! Go to Solution.
01-21-2016 10:39 PM
Hi John,
If the application traffic is not going to the WSA appliance, therefore WSA will not be able to block it.
There is possibility that the application is not using port 80/443 therefore WSA will not process the traffic and try to go direct out.
If that is the case, blocking this traffic from the border firewall will be the best bet.
You can check from the client machine that using that application by running a packet capture (such as using wireshark) to confirm where the traffic are going to.
Hope this helps.
Regards,
Handy
01-21-2016 10:39 PM
Hi John,
If the application traffic is not going to the WSA appliance, therefore WSA will not be able to block it.
There is possibility that the application is not using port 80/443 therefore WSA will not process the traffic and try to go direct out.
If that is the case, blocking this traffic from the border firewall will be the best bet.
You can check from the client machine that using that application by running a packet capture (such as using wireshark) to confirm where the traffic are going to.
Hope this helps.
Regards,
Handy
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide