cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2628
Views
4
Helpful
4
Replies

how to block web proxy and anonymizers

douglasesd
Level 1
Level 1

what is the best way to utilize the IPS to block web proxy?

4 Replies 4

bobgerman
Level 1
Level 1

The HTTP CONNECT sig should handle some of that, I think. If the proxy actually uses the HTTP CONNECT method, anyway. At very least, it can be used to block malicious users from scanning your network looking for servers with the CONNECT method enabled.

mhellman
Level 7
Level 7

Unless you interested in a full time job of maintaining a list of open proxies/anonymizers, a network IPS isn't going to be very effective at blocking access. You'd probably be better served using a subscription service (i.e. URL category filtering). Just make sure it does HTTPS CONNECT filtering as well, like another poster pointed out. In either case, if you allow outbound HTTP/HTTPS, this is almost impossible to block 100%. Any geek can setup a proxy on their home broadband.

What are the downsides to dropping any/all HTTP CONNECT attempts? Are there legitimate services that utilize this? For example will it block a internal user trying to SSL VPN to outside?

Just to clarify, are we talking about outbound user traffic that is going though a company managed non-transparent http proxy...and then utilizing an anonymous proxy? If yes, denying HTTP CONNECT will break HTTPS connections through the company managed proxy, which is unacceptable in most environments. Yes, it would prevent SSL VPN connections from working.

If instead we're talking about non-proxied or transparently proxied outbound user traffic that is simply attempting to use an RFC compliant external anonymous HTTP proxy, then preventing HTTP CONNECT should not break SSL, and might be a good thing to do. It won't necessarily stop all anonymous proxy access though...google for "CGI anonymous proxy". I don't believe it will prevent SSL VPN connections. SSL VPN's do use CONNECT requests, but I believe it's after the initial SSL connection is established (so is encrypted).

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card