- Individual Applications
Protect
Filter
Perform
Connect
Add-Ons
- Software Packages
- Complete Appliances
|
|
#11 (permalink) | |
|
Untangle Junkie
![]() Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,613
![]() |
Quote:
It just matches any traffic that matches the regex signature in the first 8 or 10 chunks of data.
__________________
Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself. If you need Untangle support please call or email support@untangle.com |
|
|
|
|
|
#15 (permalink) | |
|
Master Untangler
Join Date: Aug 2008
Posts: 277
![]() |
Quote:
Also, I am using the following version of RDP (or mstsc.exe for those who want to be extremely literal): 6.0.6001.18000 |
|
|
|
|
|
#16 (permalink) |
|
Untangle Junkie
![]() Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,613
![]() |
I'd whip out wireshark and see if this matches it
http://l7-filter.sourceforge.net/lay...tocols/rdp.pat it does say XP and 2000
__________________
Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself. If you need Untangle support please call or email support@untangle.com |
|
|
|
|
#17 (permalink) |
|
Newbie
Join Date: May 2009
Posts: 8
![]() |
Using Wireshark I was able to determine the correct signature that the new RDP client uses.
If you add an entry to the Protocol Filter containing the following signature: rdpdr.*rdpsnd.*drdynvc.*cliprdr it will begin blocking/logging RDP again. |
|
|
|
|
#18 (permalink) | |
|
Untangle Junkie
![]() Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,613
![]() |
Quote:
Great info! ![]()
__________________
Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself. If you need Untangle support please call or email support@untangle.com |
|
|
|
|
|
#19 (permalink) | |
|
Newbie
Join Date: Nov 2008
Posts: 1
![]() |
Quote:
I had an incident recently where "Administrator" logged onto a computer via remote desktop (you betcha I've changed the password) but knowing the IP address that this came from would have been a great help tracking this down. At least now if he/she/it tries again I should be able to find out the origin. Thanks! |
|
|
|
|
|
#20 (permalink) |
|
Newbie
Join Date: Aug 2009
Posts: 3
![]() |
Did you ever get an answer to your problem with VNC not being blocked? My UT is not blocking VNC either. UT just updated to 7. I have tried completely reinstalling-- protocol control still not blocking VNC. Here's my system info: Summary:
UID: 0ea4-54e8-4b3a-1172 Build: 7.0.0~svn20090924r24591release7.0-1lenny Java: 1.6.0_12 Can anyone help please? |
|
|
![]() |
| Thread Tools | |
|
|