Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Eric Leblond <eric@inl.fr>
To: Cloves Pereira Costa Jr <cloves.costa@m2sys.com.br>
Cc: Netfilter ML <netfilter@vger.kernel.org>
Subject: Re: Skype Access
Date: Wed, 6 Feb 2008 14:35:05 +0100	[thread overview]
Message-ID: <20080206133503.GB17524@bayen.regit.org> (raw)
In-Reply-To: <1202303321.5984.25.camel@wtprcwbti01002>

[-- Attachment #1: Type: text/plain, Size: 1044 bytes --]

Hello,

On Wednesday, 2008 February  6 at 11:08:41 -0200, Cloves Pereira Costa Jr wrote:
> Hi all...
> 
> I'm with some problems configuring Skype in my firewall...
> 
> I know that Skype tries to conects in high ports (>1024) everytime it
> starts. I would like to know if somenone knows a rule to configure in
> Iptables that could know what port to accept outgoing connections
> dinamicaly, in the same way that FTP does whith RELATED state.

That's simple: send an email or phone to skype people and ask them to
open their protocol and especially the part concerning port allocation.
And don't forget to ask them to make this part of the protocol go
unencrypted on the wire.

Seriously, to develop an helper module for a protocol, 2 things are
needed:
 * The protocol is known (we know where to search the information about
 port opening)
 * The protocol is clear (no crypto, we can parse information)

Skype has both problems and will never have an helper module.

BR,
-- 
Eric Leblond
INL: http://www.inl.fr/

[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

  reply	other threads:[~2008-02-06 13:35 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2008-02-06 13:08 Skype Access Cloves Pereira Costa Jr
2008-02-06 13:35 ` Eric Leblond [this message]
  -- strict thread matches above, loose matches on Subject: below --
2008-01-15  0:58 Cloves Pereira Costa Jr

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20080206133503.GB17524@bayen.regit.org \
    --to=eric@inl.fr \
    --cc=cloves.costa@m2sys.com.br \
    --cc=netfilter@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox