Endpoint Protection

 View Only
Expand all | Collapse all

How to block proxy sites through Custom IPS?

Migration User

Migration UserApr 12, 2010 02:48 PM

  • 1.  How to block proxy sites through Custom IPS?

    Posted Apr 12, 2010 12:47 PM
    We have implemented at work to block the major Social Networking sites but they are easily gotten around by using a proxy site to bypass the www.facebook.com. Is there a way other than manually adding the sites to the ICS list?


  • 2.  RE: How to block proxy sites through Custom IPS?

    Posted Apr 12, 2010 12:58 PM
    Check this thread out on how to block addresses using SEP firewall
    https://www-secure.symantec.com/connect/articles/how-block-internet-address-sep-manager-firewall-rule


  • 3.  RE: How to block proxy sites through Custom IPS?

    Posted Apr 12, 2010 01:02 PM
    Here's another.  Ultrasurf is a proxy-type application.  Here are some instructions for it.  If they do not hit head on what you need, maybe they'll give you some new ideas
    https://www-secure.symantec.com/connect/articles/most-detailed-way-block-ultrasurf


  • 4.  RE: How to block proxy sites through Custom IPS?

    Posted Apr 12, 2010 01:06 PM

    I have tried this one but it is not what I am asking. We blocked facebook but if you google proxy facebook and click on the first hit it iwll take you to a site and you enter in the blocked site and then it will serve up facebook through another site and the url won't even be in the address bar.



  • 5.  RE: How to block proxy sites through Custom IPS?

    Posted Apr 12, 2010 01:08 PM
    Great article and read but you don't even have to install anything to proxy.


  • 6.  RE: How to block proxy sites through Custom IPS?

    Posted Apr 12, 2010 01:58 PM
    This is not done via SEP, but check this out.  This may be the easiest way:
    http://perishablepress.com/press/2008/04/20/how-to-block-proxy-servers-via-htaccess/


  • 7.  RE: How to block proxy sites through Custom IPS?

    Posted Apr 12, 2010 02:18 PM


  • 8.  RE: How to block proxy sites through Custom IPS?

    Posted Apr 12, 2010 02:24 PM
    I will try this. We have run into another snag. Some sites use facebook and twitter on there site and now it is blocking those sites. Is there a way to allow these sites that have facebook or twitter embedded?


  • 9.  RE: How to block proxy sites through Custom IPS?

    Posted Apr 12, 2010 02:33 PM

    Hi Peter,

    Can you give an example of such a site. How to block it might depend on what kind of embed it is. For instance is it like a advertisement for facebook that is getting blocked or some web app that "embeds" facebook?

    Thanks,
    Grant


  • 10.  RE: How to block proxy sites through Custom IPS?

    Posted Apr 12, 2010 02:35 PM
    thechronicleherald.ca, Globe & Mail, CNN, MSNBC and Environmental News Network  to name a few.


  • 11.  RE: How to block proxy sites through Custom IPS?

    Posted Apr 12, 2010 02:37 PM
    yeah I didn't mean to block facebook.com this way, I meant to use these rules to block the proxy site addresses


  • 12.  RE: How to block proxy sites through Custom IPS?

    Posted Apr 12, 2010 02:41 PM
    Nowadays almost every site has its links to twitter and facebook so taking action per site is impossible..
    However you can try doing nslookup twitter.com it will give you local ip address for twitter in your region it might block most of the requests.


  • 13.  RE: How to block proxy sites through Custom IPS?

    Posted Apr 12, 2010 02:47 PM
    Do I still use the custom ips to do so or do I use firewall?


  • 14.  RE: How to block proxy sites through Custom IPS?

    Posted Apr 12, 2010 02:48 PM
    Use firewall..its easier to handle/Manager/configure


  • 15.  RE: How to block proxy sites through Custom IPS?

    Posted Apr 12, 2010 02:58 PM
      |   view attached
    Do you have any documentation on this. Attached is a pic of the settings I have setup.


  • 16.  RE: How to block proxy sites through Custom IPS?



  • 17.  RE: How to block proxy sites through Custom IPS?

    Posted Apr 12, 2010 03:23 PM

    I think I know what my problem was before. I had and Intrusion Prevention rule on as well. I had everything checked and this was interferring. What settings can I have checked in Intrusion Prevention and still have the firewall working.



  • 18.  RE: How to block proxy sites through Custom IPS?

    Posted Apr 12, 2010 03:44 PM
    You can have both the Rules on and they will work as long as Netowkr Threat Protection feature is installed on your machine both will work..


  • 19.  RE: How to block proxy sites through Custom IPS?

    Posted Apr 12, 2010 03:50 PM
    You might find this help full.

    Title : Symantec Endpoint Protection Manager - Intrusion Prevention - Policies explained

    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008032011043948




  • 20.  RE: How to block proxy sites through Custom IPS?

    Posted Apr 12, 2010 07:49 PM
    As soon as I withdrew the IPS everything worked like it should have. I will try it tomorrow again and see what happens.

    Thank you everyone for all of your help.


  • 21.  RE: How to block proxy sites through Custom IPS?

    Posted Apr 13, 2010 10:03 AM
    Firewalled! -
    We first started with a Host rule that defines all our internal DNS aliases, and internal proxy server hosts.
    The list was about 24 items.
    Next we use a two part fire wall rule,

    a. The allow rule, we  defined the browsers by name.exe only, we wanted to trap on name.exe only here. 
    Next we set the host rule active to filter incoming traffic only - if the browser is not recieving Tx from a defined host  or dns found in this host rule it fail to the next rule.

    b. This is the block rule, uses "*" for the application name and Application hashes of all of the browsers version found internaly - about 34 items uniques.
    This alowed us to not only stop Webproxy sites, Botnets, and forced machines to use our internal proxy, it also blocks browser that the users had renamed to avoid AD policy- it also works with our remote laptops, because we have an outfacing proxy portal, so even if the user is offline and surfing, it is managed and control via our corp proxy.  I know We'r Cool, Got the right stuff..thank you thank you..

    1. 1x host rule
    2. 2x application rules , name.exe and "*" - hash
    3. 2x firewall rules, a general alow for internal dns and proxy host, and a block all rule for the same applications.
    4. you must have a working DNS infrastructure at your company to do this and internal proxy server. this technique can be use with simpler nework implementations by using Ip ranges and hosts names only.

    This is just a overview of what my team accomplished, the purpose was to save money, no new harware or software needed to do the same function.