由买买提看人间百态

boards

本页内容为未名空间相应帖子的节选和存档,一周内的贴子最多显示50字,超过一周显示500字 访问原贴
EmergingNetworking版 - blocking skype
相关主题
BGP questionBGP 多线切换问题。。。
无法从私有IP的客户上mount 远程NFS 分区netflix太强大了 整个控制internet速度 (转载)
现在北美都有哪些ISP已经IPv6 available了?need a proxy (http)
有办法隐藏mac地址没有?现在ipv4 address里面的热门问题是什么
请教什么软件能加密p2p的链接?How does SIP phones behind firewall work
IBM to buy micromuse用一台ubuntu做proxy? (转载)
请问我有一条无线上网、一条有线上网,能否同时使用加快网速?infinistream i120
shift all outbound traffic to one BGP peerVerizon Virtually blocks China Internet
相关话题的讨论汇总
话题: skype话题: traffic话题: stun话题: blocking话题: super
进入EmergingNetworking版参与讨论
1 (共1页)
l***y
发帖数: 791
1
imho blocking skype is easy for enterprise, but not easy for ISP. skype uses
udp
extensively, with a stun-like protocol. so ISPs will have a problem. for
enterprise, out going traffic will be blocked anyway, and http/web access are
proxied. so as long as your web proxy (such as bluecoat) blocks non-http
traffic going over 80/443 port, skype will not work. (contrary to lots of
popular magazine says)
z**r
发帖数: 17771
2
One good thing is, more and more traffic management box can easiely block
those p2p traffic based on the traffic pattern instead of packet header

behind,
can
prevent
m**t
发帖数: 1292
3
good detail in the paper. I guess to block skype, block its login server
connection should do since that is centralized.

【在 z**r 的大作中提到】
: One good thing is, more and more traffic management box can easiely block
: those p2p traffic based on the traffic pattern instead of packet header
:
: behind,
: can
: prevent

l***y
发帖数: 791
4
got a link for the columbia paper?
my ethereal cap shows the skype client sending to a bunch of IPs via udp the
moment it started, and it does wait for the first to respond before it sends
the next one. so, i'm guessing it has some super-node hard-coded in the
installer/app, but there is a functionality to update the list of super-nodes,
based on feedback.
btw, to become a super-node you'll have to satisfy some criteria. i don't
think a pc behind NAT or firewall can ever become a super-node. tha

【在 z**r 的大作中提到】
: One good thing is, more and more traffic management box can easiely block
: those p2p traffic based on the traffic pattern instead of packet header
:
: behind,
: can
: prevent

z**r
发帖数: 17771
5
I think the UDP traffic you saw is the STUN detecting traffic? the link is,
arxiv.org/pdf/cs.NI/0412017

nodes,

【在 l***y 的大作中提到】
: got a link for the columbia paper?
: my ethereal cap shows the skype client sending to a bunch of IPs via udp the
: moment it started, and it does wait for the first to respond before it sends
: the next one. so, i'm guessing it has some super-node hard-coded in the
: installer/app, but there is a functionality to update the list of super-nodes,
: based on feedback.
: btw, to become a super-node you'll have to satisfy some criteria. i don't
: think a pc behind NAT or firewall can ever become a super-node. tha

z**r
发帖数: 17771
6
Not all enterprises use proxies

are

【在 l***y 的大作中提到】
: imho blocking skype is easy for enterprise, but not easy for ISP. skype uses
: udp
: extensively, with a stun-like protocol. so ISPs will have a problem. for
: enterprise, out going traffic will be blocked anyway, and http/web access are
: proxied. so as long as your web proxy (such as bluecoat) blocks non-http
: traffic going over 80/443 port, skype will not work. (contrary to lots of
: popular magazine says)

m**t
发帖数: 1292
7
interesting, are you saying Skype run over TCP port 80 ? or even worse if it
is 443 encrypted, i guess it is very difficult to tell? However how Skype do
the call control/signaling? Isn't skype using at least a signaling server?

are

【在 l***y 的大作中提到】
: imho blocking skype is easy for enterprise, but not easy for ISP. skype uses
: udp
: extensively, with a stun-like protocol. so ISPs will have a problem. for
: enterprise, out going traffic will be blocked anyway, and http/web access are
: proxied. so as long as your web proxy (such as bluecoat) blocks non-http
: traffic going over 80/443 port, skype will not work. (contrary to lots of
: popular magazine says)

z**r
发帖数: 17771
8
skype p2p engine randomly selects the port number upon installation in
addition to 80/443. And it encrypts the data using AES.
skype uses STUN and TURN to determin the type of NAT and firewall it's behind,
so it works pretty well in this situation.
However, if the gateway is a proxy, I am not clear about how STUN and TURN can
work with the proxy.
Normally the reason to block skype is about the security, skype cannot prevent
itself becoming a Super Node, that's why a lot of ppl don't like it

s

【在 l***y 的大作中提到】
: got a link for the columbia paper?
: my ethereal cap shows the skype client sending to a bunch of IPs via udp the
: moment it started, and it does wait for the first to respond before it sends
: the next one. so, i'm guessing it has some super-node hard-coded in the
: installer/app, but there is a functionality to update the list of super-nodes,
: based on feedback.
: btw, to become a super-node you'll have to satisfy some criteria. i don't
: think a pc behind NAT or firewall can ever become a super-node. tha

l***y
发帖数: 791
9
call control is encrypted. and it can use port 80/443 for that. however, it's
not riding http and it's not TLS. our enterprise proxy actually drop them on
the floor.

it
do

【在 m**t 的大作中提到】
: interesting, are you saying Skype run over TCP port 80 ? or even worse if it
: is 443 encrypted, i guess it is very difficult to tell? However how Skype do
: the call control/signaling? Isn't skype using at least a signaling server?
:
: are

z**r
发帖数: 17771
10
One good thing is, more and more traffic management box can easiely block
those p2p traffic based on the traffic pattern instead of packet header

behind,
can
prevent

【在 z**r 的大作中提到】
: skype p2p engine randomly selects the port number upon installation in
: addition to 80/443. And it encrypts the data using AES.
: skype uses STUN and TURN to determin the type of NAT and firewall it's behind,
: so it works pretty well in this situation.
: However, if the gateway is a proxy, I am not clear about how STUN and TURN can
: work with the proxy.
: Normally the reason to block skype is about the security, skype cannot prevent
: itself becoming a Super Node, that's why a lot of ppl don't like it
:
: s

m**t
发帖数: 1292
11
Reading into skype's homepage http://www.skype.com/products/explained.html
It is very vague. i am not P2P expert, don't understand how the initial
directory or "super nodes" get located/published for a skype user to start up

【在 z**r 的大作中提到】
: One good thing is, more and more traffic management box can easiely block
: those p2p traffic based on the traffic pattern instead of packet header
:
: behind,
: can
: prevent

1 (共1页)
进入EmergingNetworking版参与讨论
相关主题
Verizon Virtually blocks China Internet请教什么软件能加密p2p的链接?
[合集] BGP questionIBM to buy micromuse
关于我的电脑的IP地址的问题。请问我有一条无线上网、一条有线上网,能否同时使用加快网速?
为什么搬家后router不能用了?shift all outbound traffic to one BGP peer
BGP questionBGP 多线切换问题。。。
无法从私有IP的客户上mount 远程NFS 分区netflix太强大了 整个控制internet速度 (转载)
现在北美都有哪些ISP已经IPv6 available了?need a proxy (http)
有办法隐藏mac地址没有?现在ipv4 address里面的热门问题是什么
相关话题的讨论汇总
话题: skype话题: traffic话题: stun话题: blocking话题: super