SSL connections on Wingate

Use this forum to post questions relating to WinGate, feature requests, technical or configuration problems

Moderator: Qbik Staff

SSL connections on Wingate

Postby ian0583 » Sep 19 05 1:16 pm

How do i Filter SSL connections?
ian0583
 
Posts: 32
Joined: Sep 02 05 8:50 pm

Postby Pascal » Sep 19 05 2:44 pm

Filter? What exactly do you want to do with them?
Pascal

Qbik New Zealand
pascalv@qbik.com
http://www.qbik.com
Pascal
Qbik Staff
 
Posts: 2623
Joined: Sep 08 03 8:19 pm
Location: Auckland, New Zealand

Postby ian0583 » Sep 19 05 2:58 pm

selected ports are allowed
ian0583
 
Posts: 32
Joined: Sep 02 05 8:50 pm

Postby Pascal » Sep 19 05 3:17 pm

How do your clients connect through WinGate? And what is establishing the SSL connections?
Pascal

Qbik New Zealand
pascalv@qbik.com
http://www.qbik.com
Pascal
Qbik Staff
 
Posts: 2623
Joined: Sep 08 03 8:19 pm
Location: Auckland, New Zealand

Postby ian0583 » Sep 19 05 3:29 pm

i need to block messengers access

Client > Router >Wingate
ian0583
 
Posts: 32
Joined: Sep 02 05 8:50 pm

Postby Pascal » Sep 19 05 3:37 pm

Then it should simply be a case of using the policies for Extended Networking. If your clients are using WinGate as a simple NAT then you can specify the appropriate ports you do not want access to be granted for in advanced policies.

This post and this has some details on it. The first one is of particular interest as it has Bill's list of known applications and ports.

This gives a different method using port security actions. (Firewall)
Pascal

Qbik New Zealand
pascalv@qbik.com
http://www.qbik.com
Pascal
Qbik Staff
 
Posts: 2623
Joined: Sep 08 03 8:19 pm
Location: Auckland, New Zealand

Postby ian0583 » Sep 19 05 4:02 pm

in Bill's forum, there is a statement of blocking an application...how do i do that in wingate?
ian0583
 
Posts: 32
Joined: Sep 02 05 8:50 pm

Postby Pascal » Sep 19 05 4:07 pm

You need something on the client side to determine what application is executing. For WinGate this is t he WGIC (WinGate Internet Client) which can be installed on each client. Then you can use WRP policies to determine what applications are allowed to run.
Pascal

Qbik New Zealand
pascalv@qbik.com
http://www.qbik.com
Pascal
Qbik Staff
 
Posts: 2623
Joined: Sep 08 03 8:19 pm
Location: Auckland, New Zealand

Postby ian0583 » Sep 19 05 4:42 pm

Pascal wrote:You need something on the client side to determine what application is executing. For WinGate this is t he WGIC (WinGate Internet Client) which can be installed on each client. Then you can use WRP policies to determine what applications are allowed to run.


i already did what was in bill's forum, but Yahoo Messenger can still connect... i don't know if i have WGIC in the client PC's. is it possible to block YM even without WGIC?
ian0583
 
Posts: 32
Joined: Sep 02 05 8:50 pm

Postby Pascal » Sep 19 05 4:45 pm

If you are using ENS, simply use port security actions to deny access to the ports that Yahoo Messenger is trying to use. Check the activity window in GateKeeper to isolate the ports.
Pascal

Qbik New Zealand
pascalv@qbik.com
http://www.qbik.com
Pascal
Qbik Staff
 
Posts: 2623
Joined: Sep 08 03 8:19 pm
Location: Auckland, New Zealand

Postby ian0583 » Sep 19 05 6:48 pm

the messenger still connects to the internet...
ian0583
 
Posts: 32
Joined: Sep 02 05 8:50 pm

Postby Pascal » Sep 19 05 6:52 pm

1. What have you done to block it so far?
2. What activity do you see in GateKeeper? (Type / port / etc.)
Pascal

Qbik New Zealand
pascalv@qbik.com
http://www.qbik.com
Pascal
Qbik Staff
 
Posts: 2623
Joined: Sep 08 03 8:19 pm
Location: Auckland, New Zealand

Postby ian0583 » Sep 19 05 7:00 pm

Pascal wrote:1. What have you done to block it so far?
2. What activity do you see in GateKeeper? (Type / port / etc.)


i already added the ports used by the messenger in the ENS.
all i can see is a glimpse of a NAT connection using TCP through a certain IP which i fail to see clearly because it immediately disappers...
as of now, there is minimal activity where the only active connections are the connection to this site, and my e-mail...then i am testing the connection by using one of the clients messenger...
ian0583
 
Posts: 32
Joined: Sep 02 05 8:50 pm

Postby Pascal » Sep 19 05 7:05 pm

If you are not seeing any activity in GateKeeper that looks like it could be messenger related are you sure that the traffic is actually going out through WinGate?

You might need to look at the history pane as well to see what traffic was logged. (Or alternatively you should be seeing firewall hits)
Pascal

Qbik New Zealand
pascalv@qbik.com
http://www.qbik.com
Pascal
Qbik Staff
 
Posts: 2623
Joined: Sep 08 03 8:19 pm
Location: Auckland, New Zealand

Postby ian0583 » Sep 19 05 7:11 pm

there are connections logged in the history...
if the application was blocked, it would be recorded in the firewall riight?
there are no records of blocked access for yahoo...
right now, the only problem for me to block is the yahoo messenger...
other messengers have been successfully blocked...
ian0583
 
Posts: 32
Joined: Sep 02 05 8:50 pm

Postby Pascal » Sep 19 05 7:16 pm

If the application was being blocked it would be logged on the firewall tab, correct. Conversely, if it was accessing the internet through WinGate it should be logged in history / activity / NAT log. Can you check the NAT log file, perhaps?
Pascal

Qbik New Zealand
pascalv@qbik.com
http://www.qbik.com
Pascal
Qbik Staff
 
Posts: 2623
Joined: Sep 08 03 8:19 pm
Location: Auckland, New Zealand

Postby ian0583 » Sep 19 05 10:51 pm

yahoo messenger is a tricky program. when it is blocked from the default port, it gains access to the net through HTTP using the site "shttp.msg.yahoo.com/notify"

out of curiousity, i tried to ban it in the WWW proxy policies, and guess what, the messenger was blocked...

thank for the time and the replies...
ian0583
 
Posts: 32
Joined: Sep 02 05 8:50 pm


Return to WinGate

Who is online

Users browsing this forum: No registered users and 0 guests