Want to block P2P application using ASA5540

I want to block P2P application & IM using ASA with IPS built-in. I dont wanna use the ACL for all the ports because most of the P2P application using dynamic ports.

Aamir,
You can do this using the application layer inspection on the firewall.
Please take a look at the configuration guide given below.
http://www.cisco.com/univercd/cc/td/doc/product/multisec/asa_sw/v_7_2/conf_gd/firewall/inspect.htm#wp1479354
Rate this post, if it helps.
Cheers
Gilbert

Similar Messages

  • How to block p2p applications(Bittorent like) with AIP-SSM-10?

    Hi,
    How to block p2p application using AIP-SSM-10 working with ASA5520?AIP is on promiscuous mode.
    Thanks,
    Siva

    There are several signatures that detect p2p, for bit torrent there is 11020.0
    Yahoo triggers: 5539.0, 11200.0, 11212.0, 11217.0 & 11219.0
    etc..
    Some are disabled by default though so please ensure you enable the ones that you need.
    If you want to block these then you will have to use event actions that work in promiscuous setup for example request block connection and tcp reset. Please note that care must be taken when using these event actions.
    For more information about the event actions please refer the link below:
    http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids12/idmguide/dmevtrul.htm#wp1069467

  • I want to block gambling applications on my iphone as i have a gambling addiction

    I want to block gambling applications on my iphone as i have a gambling addiction

    If you look in Settings-->General--> Accessibility, you will see there is an option called "restrictions" or something like that.
    Ask someone who knows you to set up a code unknown to you and select in apps to authorize only 4+, 9+, 12+ and 17+ apps, since gambling apps should be available to only 18+

  • Blocking p2p application traffic and tunneling

    I need help ........
    We have taken two ASA with AIP card, and have configured Active/Active , but user are using p2p and tunneling softwares . how can we block p2p and tunneling traffic ..
    plz anyone reply me..........
    regards

    If you are using Firewall software 12.4(9)T and above, it has integrated policies to block or rate limit p2p application traffic using dynamically updateable application
    definitions for newer p2p applications. KaZaA, Gnutella, BitTorrent, and eDonkey are currently supported.
    You may also see this: http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00801e419a.shtml

  • I want to deploy an application using firefox but I don't want it set as default browser. I am using mozilla.cfg to lockdown firefox.

    I am deploying an application using firefox. I am using the mozilla.cfg file to lockdown firefox and I don't want firefox to be the default browser.

    Try the option to "Force Firefox to make itself the default" as shown in this article - http://kb.mozillazine.org/Default_browser
    Another possibility is your email application may be hard-coded to use IE.

  • Block P2P software using ASA-AIP-SSM-20 module

    Hello,
    I have got a question about blocking P2P traffic on ASA AIP module. I have searched the forums and all I could find were solutions using regex, port block, MPF, but no AIP implementation example.
    Could anyone point me in the right direction please ?
    Many thanks,
          Martin

    Hello Paps,
    Many thanks for your reply. I was searching the web like crazy for some solutions using IPS and it never occured to me that I could just simply look for the signature files on Cisco website.
    Thank you very much again
    With regards,
               Martin

  • I want to build android application using existing desktop dimension fla files. so for this I am resizing existing desktop dimension fla files to mobile dimension files but during resizing some files are resizing properly but most of the files the content

    problem definition:
    To build android application using existing desktop dimension fla fies , I am resizing that files to mobile dimension and publishing with air fo android 16  . In this process some fla's are not resizing properly I mean the content is not matching with stage
                      In one post I saw that by copying frames in movie clip we can adjust with stage . I did this and made an application but the swf's which are following the movieclip resized swf are going out of stage
    development tool : adobe flash professsional cc
    extension : air for android 16
    original file dimension: 800 * 600 px
    new dimension required is : 2650 * 1600 px ( to get full screen view)
                                           anyone please suggest me to solve this problem
    when I resized using copy frames in movie clip the output swf is coming with white screen . If I played with package it coming properly but the files which are following this are going out of stage
    Thanks&regards
    K.Niranjan

    problem definition:
    To build android application using existing desktop dimension fla fies , I am resizing that files to mobile dimension and publishing with air fo android 16  . In this process some fla's are not resizing properly I mean the content is not matching with stage
                      In one post I saw that by copying frames in movie clip we can adjust with stage . I did this and made an application but the swf's which are following the movieclip resized swf are going out of stage
    development tool : adobe flash professsional cc
    extension : air for android 16
    original file dimension: 800 * 600 px
    new dimension required is : 2650 * 1600 px ( to get full screen view)
                                           anyone please suggest me to solve this problem
    when I resized using copy frames in movie clip the output swf is coming with white screen . If I played with package it coming properly but the files which are following this are going out of stage
    Thanks&regards
    K.Niranjan

  • I want to build an application using web camera "Logitech" For that what are the steps  I had to take?? Help me...

    EID [email protected]

    Hi,
    Do you mean that you want your application to send and recieve the audio/video data online. If it is so, I think you can write applets and use them in the application. Or you can also use Macromedia Flash to do the same in a better way. For further info about Flash player please visit
    http://www.macromedia.com/software/flash/about.
    And as a reference please once visit www.mlb.com, which has some video library running on iAS.
    Hope this might have given you some poiters that help you. Should you have any further queries please get back to our software forum.
    Thanks and All the best,
    Rakesh.

  • Blocking P2P applications on WRT300N (V1)

    Hello, I am currently using a WRT300n V1 with firmware version 1.03.6. Having trouble with my room mate downloading a hell lot of stuff using bittorrent. I talked to him but he refuse to stop. I play an online game and i am getting 1000+ ping which makes it impossible to play. I tried a lot of things, including Access restrictions etc. They don't seem to work. I am using the wireless, while he is connected to port 1. I tried lowering the qos on port1 to low. Nothing seems to work. Is it something wrong with the firmware? Any help would be appreciated. Last option is to get a new connection for myself.

    Flat out doesn't work.  It's an all or nothing affair.  Either you block complete internet access between the hours noted or all days, or it's complete access to everything.  The router cannot block specific ports even though it claims it can. 

  • P2P Application

    How do i create a P2P Application using just Java Sockets

    thanks for ur concern
    By the Server Application i mean that i don't want to run a Java Server Application which accepts Client Connections.
    let me explain the program in details and also specify the problems
    1) Login is done with the help of the Username And Password -- working
    2) when login a sockets r formed to connect to all the people in the network whose IP and Username is present in the database. Thats the end of datatbase thing. No requirement of that.
    3) Now the program sets up a listener.
    4) Incase another user logs in the same steps 1) 2) 3) repeat for him/her too.
    5) The listener picks up the incoming socket and shows that the user is online.
    6) incase a socket breaks or in other words the user logs out then the Socket gives and exception which shows that the user is disconnected.
    Don't worry about the number of connections. I have streamlined that. Also you can see that the database is only access once.
    ----------- Thats the connectivity thing. -----------------------------------
    Now the filesharing part1) the user is logged in and the connections are established
    2) i use the same thing you mentioned.
    Then whats the problem???The problem is that this Program of mine works fine when the users are within a short range(say in a city) but fails outside.
    Is there a limit that an IP address can be used only in within some range or is the firewall got to do something with it??????
    Also one more question: I am using Apache as the Server Application which executes ASP Files on my PC. I want the program to run HTTPConnection to my PC and run ASP files in Apache. However this is not happening. The users within the city r also not able to connect.
    please help me and if you are interested in the code i can send you the code

  • Blocking p2p on router 877

    Hi,
    Can anyone suggest how can I effectively block p2p traffic like Ares, Limewire or other with Cisco IOS 12.4(6) or higher? I tried NBAR but I guess there is no PDLM available for Ares for instance.
    Many thanks for any suggestions.
    Remi

    Hi,
    to block p2p traffic you need to block all ports except these you really need.
    For example block all ports except http, https, smtp, pop3, dns.
    Becouse some of the p2p applications use port 80 to connect there is an options in firewall(classic or Zone-Based Policy Firewall) called protocol-violation and port-missue!
    This options prevent non-HTTP traffic over port 80.
    For Zone-Based Firewall reffer to this link:
    http://www.cisco.com/en/US/products/sw/secursw/ps1018/products_tech_note09186a00808bc994.shtml

  • Building a best practice web application using ColdFusion and Jave EE

    I've been tasked with rewriting a software using ColdFusion.  I cannot seem to find a lot of information on best practice development in ColdFusion.  I am an experience Java developer who has never used ColdFusion before.  I want to build this application using a synergy of ColdFusion and Java EE technologies.  Can someone recommend me a book that outlines how to developer in ColdFusion?  Ideally this book assumes the reader is an experienced developer with no exposure to ColdFusion.  Ideally the methods outlined in the book are still "best practice" methods.

    jaisheela wrote:
    Hello Friends,
    I am also in the same situation.
    I am a building a new web application using JSF and AJAX.
    Requirement is I need to use IBM version of DOJO and JSF but I need to develop the whole application using Eclipse 3.3,2 and Tomcat 5.5.
    With IBM version of DOJO and JSF, will Eclipse and Tomcat help to speed up the development or do you suggest me to go for Rational Application Developer and WebSphere Application Server.
    If I need to go with RAD and WAS, then I am new to RAD and WAS, is it easy to use RAD and WAS for this kind of application and implement web applicaiton fast.
    Any feedback will be great help.Those don't sound like requirements of the system to me. They sound more like someone wants to improve their CV/resume
    From what I've read recently, if it's just fast you want, look at Ruby on Rails

  • Help in creating application using BlackBerry APIs

    Hi All,
    I want to create an application using the BlackBerry APIs. Can anyone please give any pointers to any reference material or tutorials?
    Thanks in advance

    hi Bindia,
    First off all u need to install BlackBerry_JDE_4.2.1.exe which is developement environment for blackberry Application developement.
    in which u will get javadoc api reference simulator and JDE.
    Hope it helps

  • I want to be able to totally block the FaceTime functionality in my home network.  I would like to do this at the router level.  Does anyone know the hostname or IP address that the FaceTime application uses? Or which port it connects to?

    I want to be able to totally block the FaceTime functionality in my home network so my 4 kids aren't using the Facetime feature- It was easy for Skype just had to enter the work Skype on my Router Security list- and it denies access. I would like to do this at the router level for FaceTime? Only site I find in init.ess.apple.com - is this the startup site for Facetime?   Does anyone know a site I can block, hostname or IP address that the FaceTime application uses? Or which port it connects to?

    I would presume so, but it might be worth your while to experiment and play around with different combinations to see if you can block FaceTime while keeping Game Center open.  Good luck!

  • I have a game but it only for one apple id and one divece but someone i dont know id play that game and using my apple id and i want to know if u can block them from using ur apple id and also erase all the games they downlode with the apple id

    I have a game but it only for one apple id and one divece but someone i dont know id play that game and using my apple id and i want to know if u can block them from using ur apple id and also erase all the games they downlode with the apple id

    There probably is, but it requires that you be able to use punctuation and write in sentences so that we can understand exactly what you want.
    You can block others from using your Apple ID by changing your password.  There is no way to erase what was already downloaded on to someone else's device, for obvious reasons,

Maybe you are looking for

  • Getting a non-email Receipt from Mac App Store purchase

    I bought something on the app store today and realized the email that Apple has for me is not valid anymore (hotmail from years ago that I don't use).  Any way to get my receipt for the app store purchase for a reimbursement without relying on email?

  • The old folder and exclamation point

    I have read all of the posts about this problem and still nothing works. A friend of mine gave me his ipod because of this problem. He downloaded the music in windows so the is the first discrepancy. I also have no install disk to go with this. I am

  • Error massage when itunes match tries to transfer information between my PC and APPLE server

    Hi, I got an situation that whenever I try to run the itunes match, it will disconnect with an error message as the attached pic.Could you please help me out with this problem?Thx!

  • Can't use TCPIP Link Configuration

    I have my GroupWise system running on single NetWare 6.5 SP7 server. I have the link configuration set as UNC but I was told it is better to use TCPIP protocol. However, when I changed the link configuration to TCPIP and said the IP address to 192.16

  • Using magic Trackpad on older Mac osx Lion

    Considering buying Magic Trackpad to use with my Macbook 2.1 Running osx Lion with 4gb ram.  Does anyone have any experience of this combination and suggestions to if it would be a worthwhile addition. Naturally i do not have the ability to use multi