All of lore.kernel.org
 help / color / mirror / Atom feed
* Blocking Google Earth
@ 2005-08-12 20:18 fabricio bianco abreu
  2005-08-12 20:29 ` Raphael Jacquot
  0 siblings, 1 reply; 11+ messages in thread
From: fabricio bianco abreu @ 2005-08-12 20:18 UTC (permalink / raw)
  To: netfilter

Hi folks,

Is there a way to use iptables to deny access to Google Earth servers, without
blocking access to Google search engine (www.google.com)??

I have googled the Internet to find a way to do so and all I found was users
trying to configure Norton firewall to allow access to Google Earth.

Thanks in advance
________________________________________________________________

                     Fabricio Bianco Abreu 
          Núcleo de Informática e Processamento de Dados
TRIBUNAL DE CONTAS DO DISTRITO FEDERAL (http://www.tc.df.gov.br)
                   Tel 55 - 61 - 314 2236
                   Fax 55 - 61 - 314 2268
Utilize software livre (visite http://www.tc.df.gov.br/tcbrasil)        
________________________________________________________________







________ Information from NOD32 ________
This message was checked by NOD32 Antivirus System for Linux Mail Server.
http://www.nod32.com


^ permalink raw reply	[flat|nested] 11+ messages in thread
* RE: Blocking Google Earth
@ 2005-08-13 19:44 Joris Dobbelsteen
  2005-08-15  6:22 ` Jan Engelhardt
  0 siblings, 1 reply; 11+ messages in thread
From: Joris Dobbelsteen @ 2005-08-13 19:44 UTC (permalink / raw)
  To: netfilter

Other solutions might include:

* Request the user not to use the application.
* Install a HTTP proxy server that catches all port 80 traffic. Squid might be a good candidate. Here you can easily make a policy to deny access to the kh.google.com servers (it was I believe).

An advantage of a proxy is increased response times for your users (and also a little decrease in bandwidth requirements). My experience with 3 users behind it was that response times decreased and bandwidth requirements did not change (noticably). With 600+ users that situation will change significantly.
Some proxies can also limit the priority of some traffic, e.g. for kh.google.com. Unfortunally google.com doesn't allow caching of google earth traffic (sigh), I forced it on my proxy. Yeah, I know, it increases the administrative workload...

Of course, I guess you use a decent machine for routing for 600+ users.

- Joris Dobbelsteen

>-----Original Message-----
>From: netfilter-bounces@lists.netfilter.org 
>[mailto:netfilter-bounces@lists.netfilter.org] On Behalf Of 
>Thilo Schulz
>Sent: zaterdag, 13 augustus 2005 17:11
>To: netfilter@lists.netfilter.org
>Subject: Re: Blocking Google Earth
>
>On Saturday 13 August 2005 16:14, Leonardo Rodrigues Magalhães wrote:
>>     I really dont think it's easy to limit bandwidth usage ONLY for 
>> Earth Google without making bad experiencies on doing 
>searchs on Google.
>> No matter if searches are low-bandwidth. If you get some QoS 
>and band 
>> limitation on google IPs, be sure that your google earth users will 
>> use ALL the available bandwidth, thus making google earth as well as 
>> google serching probably extremely slow.
>
>He only had that problem with one single user. Likewise, he 
>can restrict bandwidth to google only for that one single user 
>too. Like I already said, your proxy method can be easily 
>circumvented using something like an SSL proxy after your 
>proxy, whereas QoS can selectively keep a user from unfairly 
>exceeding certain bandwidth. This will not only solve problems 
>with the http protocol, but also problems with the user using 
>too much bandwidth in general.
>
>--
>Thilo Schulz
>


^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2005-08-15  6:22 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-08-12 20:18 Blocking Google Earth fabricio bianco abreu
2005-08-12 20:29 ` Raphael Jacquot
2005-08-12 22:38   ` fabricio bianco abreu
2005-08-13  2:31     ` Thilo Schulz
2005-08-12 23:59       ` Eric Scopinho
2005-08-13 12:32       ` Jan Engelhardt
2005-08-14  1:15         ` Dwayne Hottinger
2005-08-13 14:14       ` Leonardo Rodrigues Magalhães
2005-08-13 15:11         ` Thilo Schulz
  -- strict thread matches above, loose matches on Subject: below --
2005-08-13 19:44 Joris Dobbelsteen
2005-08-15  6:22 ` Jan Engelhardt

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.