Old 04-09-2009, 09:20 PM   #11 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,613
dmorris is on a distinguished road
Default

Quote:
Originally Posted by datdamnmachine View Post

Also, will it only log internal traffic going out the external interface or will it also log external traffic coming in the external and going out the internal?
It doesn't care about direction.

It just matches any traffic that matches the regex signature in the first 8 or 10 chunks of data.
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
dmorris is offline  
Old 04-10-2009, 11:03 AM   #12 (permalink)
Master Untangler
 
Join Date: Aug 2008
Posts: 277
datdamnmachine is on a distinguished road
Default

Quote:
Originally Posted by dmorris View Post
It doesn't care about direction.

It just matches any traffic that matches the regex signature in the first 8 or 10 chunks of data.
Well then I do know that RDP in both directions doesn't get logged.
datdamnmachine is offline  
Old 04-18-2009, 06:13 PM   #13 (permalink)
255
Untanglit
 
Join Date: Apr 2009
Location: Hamilton, New Zealand
Posts: 16
255 is on a distinguished road
Send a message via MSN to 255
Default

Have to be honest that I seem to have a similar issue with protocol logging. I only seem to be getting a selective few protocols that are logging.
__________________
Codeblue, New Zealand
L1, 36 Bryce St
Hamilton
+64 7 9292200
255 is offline  
Old 05-18-2009, 11:41 PM   #14 (permalink)
Untangler
 
Join Date: Jun 2008
Posts: 52
Skathen is on a distinguished road
Default

Mine is logging XP fine, Vista it just ignores, same rules apply to both sets of users.
Skathen is offline  
Old 05-19-2009, 07:06 PM   #15 (permalink)
Master Untangler
 
Join Date: Aug 2008
Posts: 277
datdamnmachine is on a distinguished road
Default

Quote:
Originally Posted by Skathen View Post
Mine is logging XP fine, Vista it just ignores, same rules apply to both sets of users.
On yours, are you using RDP over TLS? If that is the case then because the traffic is over TLS, it MIGHT not be detecting it. I'm no developer of the product but there could be an issue there.

Also, I am using the following version of RDP (or mstsc.exe for those who want to be extremely literal):

6.0.6001.18000
datdamnmachine is offline  
Old 05-19-2009, 10:37 PM   #16 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,613
dmorris is on a distinguished road
Default

I'd whip out wireshark and see if this matches it

http://l7-filter.sourceforge.net/lay...tocols/rdp.pat

it does say XP and 2000
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
dmorris is offline  
Old 05-28-2009, 02:25 PM   #17 (permalink)
Newbie
 
Join Date: May 2009
Posts: 8
lbgaus is on a distinguished road
Default

Using Wireshark I was able to determine the correct signature that the new RDP client uses.

If you add an entry to the Protocol Filter containing the following signature:

rdpdr.*rdpsnd.*drdynvc.*cliprdr

it will begin blocking/logging RDP again.
lbgaus is offline  
Old 07-02-2009, 08:38 AM   #18 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,613
dmorris is on a distinguished road
Default

Quote:
Originally Posted by lbgaus View Post
Using Wireshark I was able to determine the correct signature that the new RDP client uses.

If you add an entry to the Protocol Filter containing the following signature:

rdpdr.*rdpsnd.*drdynvc.*cliprdr

it will begin blocking/logging RDP again.
I missed this post.
Great info!

__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
dmorris is offline  
Old 09-20-2009, 06:55 AM   #19 (permalink)
Newbie
 
Join Date: Nov 2008
Posts: 1
BucK is on a distinguished road
Default

Quote:
Originally Posted by lbgaus View Post
Using Wireshark I was able to determine the correct signature that the new RDP client uses.

If you add an entry to the Protocol Filter containing the following signature:

rdpdr.*rdpsnd.*drdynvc.*cliprdr

it will begin blocking/logging RDP again.
I'm running Build: 6.2.0~svn20090527r23446release6.2-1lenny and had to change the signature to this also - great information.

I had an incident recently where "Administrator" logged onto a computer via remote desktop (you betcha I've changed the password) but knowing the IP address that this came from would have been a great help tracking this down. At least now if he/she/it tries again I should be able to find out the origin.

Thanks!
BucK is offline  
Old 10-22-2009, 07:25 AM   #20 (permalink)
Newbie
 
Join Date: Aug 2009
Posts: 3
Carolyn Steen is on a distinguished road
Default

Did you ever get an answer to your problem with VNC not being blocked? My UT is not blocking VNC either. UT just updated to 7. I have tried completely reinstalling-- protocol control still not blocking VNC. Here's my system info: Summary:
UID: 0ea4-54e8-4b3a-1172
Build: 7.0.0~svn20090924r24591release7.0-1lenny

Java: 1.6.0_12

Can anyone help please?
Carolyn Steen is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 03:23 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2