Most companies deny all but specific ports. For example, block all
ports, allow port 80 and 443 for everyone, then allow specific servers
to get out to services they need (25 for mail, 53 for dns, 80/443 for
proxy/webfilter, etc).
That won't stop everyone and everything, but its a good start. A
smart user can always tunnel over port 80, icmp, or whatever you have
open, that's where a good webfilter/proxy comes into play, and don't
let the users get to anywhere directly.
HTH
Charles
On Wed, Oct 14, 2009 at 1:48 PM, Jessica Aguilar <jaguilar at skyriver dot net> wrote:
>
>
>
>
> Hello Support
>
>
>
>
>
> I am having a problem one somebody is downloading copyright information
> from website and I need to block all p2p programs any one knows how?
>
>
>
> I already did the traffic shaping but that only does the priority
> right?
>
>
>
>
>
> Thank you,
>
>
|