From mboxrd@z Thu Jan 1 00:00:00 1970 From: Khanh Tran Subject: RE: Blocking downloads Date: Wed, 5 Feb 2003 11:06:45 -0500 Sender: netfilter-admin@lists.netfilter.org Message-ID: <01CEA3A5B8B2D511890F0002A5870AEC64EBAD@EXCHANGE> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----_=_NextPart_001_01C2CD30.94E2EFE0" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: 'ASC - Ronald Roeleveld' Cc: "'netfilter@lists.netfilter.org'" This message is in MIME format. Since your mail reader does not understand this format, some or all of this message may not be legible. ------_=_NextPart_001_01C2CD30.94E2EFE0 Content-Type: text/plain; charset="iso-8859-1" Well, that is going to be a little rough since most file downloads happen over the same port as the http traffic (port 80). You could block all ports besides 80, but they'd still be able to download files that were http links. You might want to look into setting file permissions or doing some kind of kiosk-mode on your local workstations. Khanh Tran Network Operations Sarah Lawrence College 1 Mead Way Bronxville, NY 10708 (914) 395-2639 -----Original Message----- From: ASC - Ronald Roeleveld [mailto:r.roeleveld@ascinternational.nl] Sent: Wednesday, February 05, 2003 11:02 AM To: 'Khanh Tran' Cc: 'netfilter@lists.netfilter.org' Subject: RE: Blocking downloads What I want is that clients cannot, let's say with Internet Explorer or Mozzila, download files from the internet, but can browse the internet. -----Original Message----- From: Khanh Tran [mailto:khanh@slc.edu] Sent: woensdag 5 februari 2003 16:45 To: 'ASC - Ronald Roeleveld'; 'netfilter@lists.netfilter.org' Subject: RE: Blocking downloads You can very easily block certain clients based on either MAC address and/or IP address. As for the ports, well that depends on the application you want to block (ie. FTP, Kazaa, web, NNTP, etc). Khanh Tran Network Operations Sarah Lawrence College -----Original Message----- From: ASC - Ronald Roeleveld [mailto:r.roeleveld@ascinternational.nl] Sent: Wednesday, February 05, 2003 10:38 AM To: 'netfilter@lists.netfilter.org' Subject: Blocking downloads Hey everyone, Since I want to spare my download speed, and dont want clients to download freaking warez, would it be possible to block downloads with iptables for certain clients??? And if it's possible which ports need to closed? Thanks in advance, Ronald Roeleveld System Administrator ASCINTERNATIONAL Vlietweg 17c, 2266 KA, Leidschendam, The Netherlands Tel. +31 (0)70 3178400, Fax +31 (0)70 3204760 E-mail: r.roeleveld@ascinternational.nl , Website: http://www.ascinternational.nl ------_=_NextPart_001_01C2CD30.94E2EFE0 Content-Type: text/html; charset="iso-8859-1"
Well, that is going to be a little rough since most file downloads happen over the same port as the http traffic (port 80).  You could block all ports besides 80, but they'd still be able to download files that were http links.  You might want to look into setting file permissions or doing some kind of kiosk-mode on your local workstations.
 

Khanh Tran
Network Operations
Sarah Lawrence College
1 Mead Way
Bronxville, NY 10708
(914) 395-2639

-----Original Message-----
From: ASC - Ronald Roeleveld [mailto:r.roeleveld@ascinternational.nl]
Sent: Wednesday, February 05, 2003 11:02 AM
To: 'Khanh Tran'
Cc: 'netfilter@lists.netfilter.org'
Subject: RE: Blocking downloads

What I want is that clients cannot, let's say with Internet Explorer or Mozzila, download files from the internet, but can browse the internet.
 
-----Original Message-----
From: Khanh Tran [mailto:khanh@slc.edu]
Sent: woensdag 5 februari 2003 16:45
To: 'ASC - Ronald Roeleveld'; 'netfilter@lists.netfilter.org'
Subject: RE: Blocking downloads

You can very easily block certain clients based on either MAC address and/or IP address.  As for the ports, well that depends on the application you want to block (ie. FTP, Kazaa, web, NNTP, etc).
 

Khanh Tran
Network Operations
Sarah Lawrence College

-----Original Message-----
From: ASC - Ronald Roeleveld [mailto:r.roeleveld@ascinternational.nl]
Sent: Wednesday, February 05, 2003 10:38 AM
To: 'netfilter@lists.netfilter.org'
Subject: Blocking downloads

Hey everyone,
 
Since I want to spare my download speed, and dont want clients to download freaking warez, would it be possible to block downloads with iptables for certain clients???
And if it's possible which ports need to closed?
 
Thanks in advance,

Ronald Roeleveld 
System Administrator 

ASCINTERNATIONAL
Vlietweg 17c, 2266 KA, Leidschendam, The Netherlands
Tel. +31 (0)70 3178400, Fax +31 (0)70 3204760
E-mail: r.roeleveld@ascinternational.nl, Website: http://www.ascinternational.nl

 
------_=_NextPart_001_01C2CD30.94E2EFE0--