PDA

View Full Version : Possible bug with IPS in Blocking Gmail chat?


Saleem
11-05-2008, 04:37 AM
Hi,
I enabled the block in IPS for the following things,

(Potential Corporate Privacy Violation)
1. Google Chat web client connection -> SID 12303
2. Google Webmail client chat applet -> SID 12391
3. Yahoo Messenger web client connection -> SID 12305
4. Yahoo Webmail client chat applet -> SID 12390
and few others for Msn messenger webclient and AOL instant messenger web client.

I've blocked those Yahoo, MSN and Jabber protocols under the Protocol control.

Now people were unable to chat from the installed Yahoo messenger, Google's Gtalk and MSN Messengers. [ :worship: to Protocol control]


However the problem is really with web clients. They are working seamlessly without any issues even though they're blocked in IPS.

Any suggestions? I wanted to use Gmail, Yahoo mail and MSN mail without the chat support.

Similar post is found at http://forums.untangle.com/showthread.php?t=5740 stating events are not matched/ not working..

I am using Untangle 5.3 in Routing mode as standalone server.

Another interesting finding is, in the Intrusion Prevention's event log shows that gmail chat is blocked, where as it is not.

mdh
11-05-2008, 09:06 PM
Do a Google search with the name of the client in quotes and the word "ports". You will likely find listings of ports that are used as well as specific hostnames/IPs that need to be blocked.

Saleem
11-05-2008, 10:10 PM
Gmail uses https now a days :( They have an option to turn it https always on. Also it shows it is blocked in the intrusion prevention's event log. This is what I wonder.