Petri.co.il forums by Daniel Petri  

Petri.co.il forums Home Forums Start Page Forums Frequently Asked Questions FAQ Member List Members List
Go Back   Petri.co.il forums by Daniel Petri > Networking > Cisco Security – PIX/ASA/VPN
Petri.co.il is happy to award Virtual the title of Most Valuable Member !!!
Register Calendar Calendar Search Petri.co.il forums by Daniel Petri Search Today's Posts Mark Forums Read

Notices

IDEALSTOR
Blocking Spotify on Cisco PIX ASA

Blocking Spotify on Cisco PIX ASA

this thread has 4 replies and has been viewed 2995 times

Closed Thread
 
Thread Tools Search this Thread Display Modes
  #1  
Old 31st July 2009, 18:42
emalbon emalbon is offline
Casual
Casual
 
 Join Date: Jul 2009
  6 month star 12 month star
 Location: Nottingham, UK
 Posts: 4
 Reputation: emalbon is on a distinguished road (10)
Default Blocking Spotify on Cisco PIX ASA

Hi All,

I'm a complete noob with Cisco routers and I am hoping to find a way to block Spotify from our company firewall. Our bandwidth has been suffering severely over the last month and we have our suspicions this is the reason.

Device is Cisco ADSM 5.2
ASA Version 7.2

I am aware of the following :
-Spotify own a range of addresses (all of 78.31.8.0/22)
-Spotify tries to connect on port 4070. If that is blocked, it will then try port 443, if that's blocked, then port 80
-Spotify can use a proxy, so you need to block socks and https access to the ap.spotify.com address

Can anyone point me in the right direction for what I need to do here? Bear in mind I may need to be spoon fed commands here. I'm not even sure if this is possible, as surely we can't block ports 80 and 443?

Feel free to ask any more information!
  #2  
Old 4th August 2009, 21:50
Dumber's Avatar
Dumber Dumber is offline
Moderator
 
 Join Date: Dec 2003
  6 month star 12 month star
 Location: The Netherlands
 Posts: 7,500
 Reputation: Dumber is a splendid one to beholdDumber is a splendid one to beholdDumber is a splendid one to beholdDumber is a splendid one to beholdDumber is a splendid one to beholdDumber is a splendid one to beholdDumber is a splendid one to behold (737)
Default Re: Blocking Spotify on Cisco PIX ASA

Moved to Cisco Security.
__________________
Marcel
Netherlands
http://www.phetios.com

MCTS, MCITP(EA, SA), MCP, MCSA 2003:Security, MCSE 2003:Security, CCNA, CCSA, CCSE, CCSE+
No matter how secure, there is always the human factor.
  #3  
Old 6th August 2009, 20:31
Daze Daze is offline
Junior Member
It's not a coincidence
 
 Join Date: Jun 2006
  6 month star 12 month star
 Posts: 123
 Reputation: Daze is on a distinguished road (25)
Default Re: Blocking Spotify on Cisco PIX ASA

Ok, here is an example:

Code:
PIX#
PIX#conf t
PIX(config)# access-list Deny-Spotify extended deny ip any 78.31.8.0 255.255.252.0
PIX(config)# access-list Deny-Spotify extended permit ip any any
PIX(config)# access-group Deny-Spotify out interface inside
PIX(config)#
That access-list will block ip range (78.31.8.0 - 78.31.11.255)
__________________
CCNA, Network+
  #4  
Old 11th August 2009, 11:18
emalbon emalbon is offline
Casual
Casual
 
 Join Date: Jul 2009
  6 month star 12 month star
 Location: Nottingham, UK
 Posts: 4
 Reputation: emalbon is on a distinguished road (10)
Default Re: Blocking Spotify on Cisco PIX ASA

Hi Daze,

That's great, thank you so much. Can I confirm that will stop access from the inside out?

Is there still any need to block the various ports that Spotify uses or access to the ap.spotify.com address that Spotify uses?

Thanks again for your assistance.
  #5  
Old 11th August 2009, 12:48
gforceindustries's Avatar
gforceindustries gforceindustries is offline
Senior Member
Wrote the book
 
 Join Date: Sep 2008
  6 month star 12 month star
 Location: Leics, UK
 Posts: 3,808
 Reputation: gforceindustries has a spectacular aura aboutgforceindustries has a spectacular aura about (198)
Default Re: Blocking Spotify on Cisco PIX ASA

Quote:
Originally Posted by emalbon View Post
ap.spotify.com
If you ping it, you'll see that it's in the blocked IP range.
__________________
Gareth Howells

BSc (Hons)

Any advice is given in good faith and without warranty.

Please give reputation points if somebody has helped you.

"For by now I could have stretched out my hand and struck you and your people with a plague that would have wiped you off the Earth." (Exodus 9:15) - I could kill you with my thumb.

"Everything that lives and moves will be food for you." (Genesis 9:3) - For every animal you don't eat, I'm going to eat three.
Closed Thread


Go Back
Petri.co.il forums by Daniel Petri > Networking > Cisco Security – PIX/ASA/VPN


Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Cisco ASA Translation (WAS: Re: ASA 5505 Port Forwarding, NAT error) rgpone Cisco Security – PIX/ASA/VPN 3 17th March 2009 13:05
ASA - Blocking LAN Traffic support@cm8.net Cisco Security – PIX/ASA/VPN 5 6th March 2009 17:27
Free ASA/PIX simulators ? sco1984 Cisco Certification Track 4 21st September 2007 23:47
PIX blocking only some emails chief007 Cisco Security – PIX/ASA/VPN 3 15th May 2007 13:17
PIX vs ASA daviddavis Cisco Security – PIX/ASA/VPN 0 2nd June 2006 21:26



All times are GMT +3. The time now is 06:13.

Steel Blue Style vBulletin Style ©2006 vBEnhanced Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
 

Valid XHTML 1.0!   Valid CSS!

Copyright 2005 Daniel Petri