Poll

how can i block ultrasoft in EBOX?

alo
0 (0%)
alo
0 (0%)

Total Members Voted: 0

Voting closed: March 22, 2010, 06:59:21 pm

Author Topic: ultrasoft and Ebox  (Read 2470 times)

ps2ali

  • Zen Apprentice
  • *
  • Posts: 3
  • Karma: +0/-0
    • View Profile
ultrasoft and Ebox
« on: March 16, 2010, 06:59:21 pm »
hi everybody;

i m now install ebox and i tested and its works fine ,actualy i want to block one software like ultrasurf , i hope someone give me help  

thanks

Marcus

  • Forum Moderator
  • Zen Samurai
  • *****
  • Posts: 395
  • Karma: +12/-0
    • View Profile
    • Professional IT Service
Re: ultrasoft and Ebox
« Reply #1 on: March 18, 2010, 02:32:14 am »
Block outbound port #9666 and that should do the trick

ps2ali

  • Zen Apprentice
  • *
  • Posts: 3
  • Karma: +0/-0
    • View Profile
Re: ultrasoft and Ebox
« Reply #2 on: March 18, 2010, 08:41:58 am »
ultrasurf had a random ports ,i tried with 9666 but no way , whats the solution ,this is a big issue because how this firewall can will be effectual ?

Squeaner

  • Guest
Re: ultrasoft and Ebox
« Reply #3 on: March 21, 2010, 03:56:31 am »
UltraSurf uses https to create the initial connection.  You would need to disable all outbound https traffic and manually use the proxy setting for https in the browser in order to get around that issue.  I had to do this not with Ebox, but another system used at a school district.

Hope this helps.

ps2ali

  • Zen Apprentice
  • *
  • Posts: 3
  • Karma: +0/-0
    • View Profile
Re: ultrasoft and Ebox
« Reply #4 on: March 21, 2010, 09:31:13 am »
if i do that the  email in my company  doesn't work because its https ,i tried but no way ???

whoiam55

  • Zen Apprentice
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
Re: ultrasoft and Ebox
« Reply #5 on: March 22, 2010, 07:29:27 pm »
Hi there, I'm rather new to eBox so I don't know much about it, but for ultrasurf, if I were on a windows domain, I would block ultrasurf application using software restriction policies with application hash rule. I don't know if same can be cooked up with eBox domain.

Other way is to block SSL (Port 443) it may be easier to deny all https sites (using squid) and set up a https Allowed list. The number of https sites users are likely to want to access would be very minimal and your HTTPS Allowed list would not be too difficult to maintain.