Linux Netfilter discussions
 help / color / mirror / Atom feed
* Skype Access
@ 2008-01-15  0:58 Cloves Pereira Costa Jr
  0 siblings, 0 replies; 3+ messages in thread
From: Cloves Pereira Costa Jr @ 2008-01-15  0:58 UTC (permalink / raw)
  To: netfilter ML

Hi all...

I'm with some problems configuring Skype in my firewall...

I know that Skype tries to conects in high ports (>1024) everytime it
starts. I would like to know if somenone knows a rule to configure in
Iptables that could know what port to accept outgoing connections
dinamicaly, in the same way that FTP does in passive conections.

Thx in advance

-

Cloves Jr



^ permalink raw reply	[flat|nested] 3+ messages in thread

* Skype Access
@ 2008-02-06 13:08 Cloves Pereira Costa Jr
  2008-02-06 13:35 ` Eric Leblond
  0 siblings, 1 reply; 3+ messages in thread
From: Cloves Pereira Costa Jr @ 2008-02-06 13:08 UTC (permalink / raw)
  To: Netfilter ML

Hi all...

I'm with some problems configuring Skype in my firewall...

I know that Skype tries to conects in high ports (>1024) everytime it
starts. I would like to know if somenone knows a rule to configure in
Iptables that could know what port to accept outgoing connections
dinamicaly, in the same way that FTP does whith RELATED state.

Thx in advance

-

Cloves Jr

-- 
Cloves Pereira Costa Jr
M2Sys Tecnologia

+55 41 3271-4400
+55 41 8413-6740
www.m2sys.com.br
cloves.costa@m2sys.com.br


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: Skype Access
  2008-02-06 13:08 Cloves Pereira Costa Jr
@ 2008-02-06 13:35 ` Eric Leblond
  0 siblings, 0 replies; 3+ messages in thread
From: Eric Leblond @ 2008-02-06 13:35 UTC (permalink / raw)
  To: Cloves Pereira Costa Jr; +Cc: Netfilter ML

[-- Attachment #1: Type: text/plain, Size: 1044 bytes --]

Hello,

On Wednesday, 2008 February  6 at 11:08:41 -0200, Cloves Pereira Costa Jr wrote:
> Hi all...
> 
> I'm with some problems configuring Skype in my firewall...
> 
> I know that Skype tries to conects in high ports (>1024) everytime it
> starts. I would like to know if somenone knows a rule to configure in
> Iptables that could know what port to accept outgoing connections
> dinamicaly, in the same way that FTP does whith RELATED state.

That's simple: send an email or phone to skype people and ask them to
open their protocol and especially the part concerning port allocation.
And don't forget to ask them to make this part of the protocol go
unencrypted on the wire.

Seriously, to develop an helper module for a protocol, 2 things are
needed:
 * The protocol is known (we know where to search the information about
 port opening)
 * The protocol is clear (no crypto, we can parse information)

Skype has both problems and will never have an helper module.

BR,
-- 
Eric Leblond
INL: http://www.inl.fr/

[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2008-02-06 13:35 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-01-15  0:58 Skype Access Cloves Pereira Costa Jr
  -- strict thread matches above, loose matches on Subject: below --
2008-02-06 13:08 Cloves Pereira Costa Jr
2008-02-06 13:35 ` Eric Leblond

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox