由买买提看人间百态

boards

本页内容为未名空间相应帖子的节选和存档,一周内的贴子最多显示50字,超过一周显示500字 访问原贴
EmergingNetworking版 - 这websense也太厉害了吧
相关主题
need a proxy (http)The next broadband killer: advanced operating systems?
Juniper/NetScreen 5GT-WLAN for homeppstream 点播功能是怎么实现p2p的?
怎么绕过proxy,看IP请教ASA5510 配置
J家的Virtual FW貌似很给力从公司remote家里电脑
求一个可用的HTTP代理one IPv4 address costs $11.25 now
blocking skype求推荐远程桌面/远程控制软件,免费,越内网,可运行在独立用户下
Ethernet MAC and IP address请教一个VPN的问题
现在virtulization似乎很火啊如果你的大陆亲友不能上mitbbs,请向他们推荐aplusproxy
相关话题的讨论汇总
话题: websense话题: ip话题: block话题: addresses话题: proxy
进入EmergingNetworking版参与讨论
1 (共1页)
j*e
发帖数: 1987
1
公司服务器上装了websense,搞得我所有的BBS,下载站点,stream media站点等等全
都上不去,MSN不能用,web的MSN也全都失效。然后想用proxy绕过也绕不过。一直以来
用logmein登录自己家的电脑上这些,现在居然也登录不了,真是赶尽杀绝啊。
大侠有没有什么办法支支招啊?
谢谢了!
z**r
发帖数: 17771
2
get a ssl based vpn server on your home machine

【在 j*e 的大作中提到】
: 公司服务器上装了websense,搞得我所有的BBS,下载站点,stream media站点等等全
: 都上不去,MSN不能用,web的MSN也全都失效。然后想用proxy绕过也绕不过。一直以来
: 用logmein登录自己家的电脑上这些,现在居然也登录不了,真是赶尽杀绝啊。
: 大侠有没有什么办法支支招啊?
: 谢谢了!

Z****e
发帖数: 2999
3
加密proxy啊:自己在家架个linux的proxy,比如用squid,然后再公司弄个SSH tunnel
到家里,这样你公司的browser就连接本机的端口,但实际被加密映射到了家里的proxy
端口,除非公司block你家IP/域名

【在 j*e 的大作中提到】
: 公司服务器上装了websense,搞得我所有的BBS,下载站点,stream media站点等等全
: 都上不去,MSN不能用,web的MSN也全都失效。然后想用proxy绕过也绕不过。一直以来
: 用logmein登录自己家的电脑上这些,现在居然也登录不了,真是赶尽杀绝啊。
: 大侠有没有什么办法支支招啊?
: 谢谢了!

s*********4
发帖数: 1980
4
没用,Admin可以设置POLICY,只要是从楼主的公司IP里出来的,去往任何不可知IP的
REQUEST一律BLOCK.

tunnel
proxy

【在 Z****e 的大作中提到】
: 加密proxy啊:自己在家架个linux的proxy,比如用squid,然后再公司弄个SSH tunnel
: 到家里,这样你公司的browser就连接本机的端口,但实际被加密映射到了家里的proxy
: 端口,除非公司block你家IP/域名

c**t
发帖数: 2744
5
说说有没有后门?

【在 s*********4 的大作中提到】
: 没用,Admin可以设置POLICY,只要是从楼主的公司IP里出来的,去往任何不可知IP的
: REQUEST一律BLOCK.
:
: tunnel
: proxy

z**r
发帖数: 17771
6
of coz you can do this, but this doesn't make sense. the point is to block
some non-work related access based on the *content*, so, ssl based vpn can
easily bypass websense

【在 s*********4 的大作中提到】
: 没用,Admin可以设置POLICY,只要是从楼主的公司IP里出来的,去往任何不可知IP的
: REQUEST一律BLOCK.
:
: tunnel
: proxy

s*********4
发帖数: 1980
7
It is not simply based on "content". The content has been pre-categoried
into a database. At runtime you are blocked by user or source IP combined
with detination IP (of course there are other more complicated policies you
can do). An unknown detination IP such as your proxy will be identified as "
uncategorized" and could be set to block regarless HTTP or HTTPS or any
other protocols (any port).

【在 z**r 的大作中提到】
: of coz you can do this, but this doesn't make sense. the point is to block
: some non-work related access based on the *content*, so, ssl based vpn can
: easily bypass websense

z**r
发帖数: 17771
8
you didn't get my point, I said "of coz you can do this, but this doesn't
make sense".
what are known addresses or unknown addresses? the address space changes
everyday... so the only way that works is, block all addresses and enable
some "known" addresses. This is a piece of a cake for a firewall, so tell me
why I need to buy websense?
dealing with layer 3/4 is not wise as far as filtering Internet access...

you
"

【在 s*********4 的大作中提到】
: It is not simply based on "content". The content has been pre-categoried
: into a database. At runtime you are blocked by user or source IP combined
: with detination IP (of course there are other more complicated policies you
: can do). An unknown detination IP such as your proxy will be identified as "
: uncategorized" and could be set to block regarless HTTP or HTTPS or any
: other protocols (any port).

s**********9
发帖数: 1238
9

me
对啊,没错,我明白你意思,普通防火墙都可以干BLOCK 未知IP这个事了。
可能这个websense就是一个简化版的软件防火墙!

【在 z**r 的大作中提到】
: you didn't get my point, I said "of coz you can do this, but this doesn't
: make sense".
: what are known addresses or unknown addresses? the address space changes
: everyday... so the only way that works is, block all addresses and enable
: some "known" addresses. This is a piece of a cake for a firewall, so tell me
: why I need to buy websense?
: dealing with layer 3/4 is not wise as far as filtering Internet access...
:
: you
: "

n*w
发帖数: 3393
10
ssh port 被禁用,不能ssh出去有什么办法?

tunnel
proxy

【在 Z****e 的大作中提到】
: 加密proxy啊:自己在家架个linux的proxy,比如用squid,然后再公司弄个SSH tunnel
: 到家里,这样你公司的browser就连接本机的端口,但实际被加密映射到了家里的proxy
: 端口,除非公司block你家IP/域名

相关主题
blocking skypeThe next broadband killer: advanced operating systems?
Ethernet MAC and IP addressppstream 点播功能是怎么实现p2p的?
现在virtulization似乎很火啊请教ASA5510 配置
进入EmergingNetworking版参与讨论
s*********4
发帖数: 1980
11
The known IP addresses have been identified in Websense database. Any IP
addresses (mapped to various domains) that are not included in Websense
database are identified as "unknown" thus can be set to block, regardless
ports.
You have a logic (not technical) concept misunderstanding. Websene can do
layer 3 filtering doesn't mean it can ONLY do layer 3 filtering. Also in
enterprise environment the customers may install similar systems from
multiple vendors. For example, proxy chainning, multiple

【在 z**r 的大作中提到】
: you didn't get my point, I said "of coz you can do this, but this doesn't
: make sense".
: what are known addresses or unknown addresses? the address space changes
: everyday... so the only way that works is, block all addresses and enable
: some "known" addresses. This is a piece of a cake for a firewall, so tell me
: why I need to buy websense?
: dealing with layer 3/4 is not wise as far as filtering Internet access...
:
: you
: "

p*****n
发帖数: 242
12
zher 可是活跃在未名的每个版块。

【在 z**r 的大作中提到】
: get a ssl based vpn server on your home machine
Z****e
发帖数: 2999
13
我不是说了么block ip就没用了么,呵呵

【在 s*********4 的大作中提到】
: 没用,Admin可以设置POLICY,只要是从楼主的公司IP里出来的,去往任何不可知IP的
: REQUEST一律BLOCK.
:
: tunnel
: proxy

Z****e
发帖数: 2999
14
用什么port可以自己选啊,非要22不可么

【在 n*w 的大作中提到】
: ssh port 被禁用,不能ssh出去有什么办法?
:
: tunnel
: proxy

c*****r
发帖数: 142
15
没错。就用80,如果websense有protocol discovery,找fake webserver实际上是ssh
server,拿到key以后就应该通过了。

【在 Z****e 的大作中提到】
: 用什么port可以自己选啊,非要22不可么
s*********4
发帖数: 1980
16
没用,是IP + Port block.

ssh

【在 c*****r 的大作中提到】
: 没错。就用80,如果websense有protocol discovery,找fake webserver实际上是ssh
: server,拿到key以后就应该通过了。

n*w
发帖数: 3393
17
好像只有80和https可以出去。以前试过"connect.c"+ssh但是还是出不去。

【在 Z****e 的大作中提到】
: 用什么port可以自己选啊,非要22不可么
z**r
发帖数: 17771
18
俺知道websense可以block IP,俺的意思是,没这个必要,每个产品都有特色,干自己
专长的比较好,另外,俺质疑这种block all unknown IP的policy是不是真的有公司会用

【在 s*********4 的大作中提到】
: The known IP addresses have been identified in Websense database. Any IP
: addresses (mapped to various domains) that are not included in Websense
: database are identified as "unknown" thus can be set to block, regardless
: ports.
: You have a logic (not technical) concept misunderstanding. Websene can do
: layer 3 filtering doesn't mean it can ONLY do layer 3 filtering. Also in
: enterprise environment the customers may install similar systems from
: multiple vendors. For example, proxy chainning, multiple

z**r
发帖数: 17771
19
其实就那么2、3个,碰巧你也去这几个版,呵呵

【在 p*****n 的大作中提到】
: zher 可是活跃在未名的每个版块。
z**r
发帖数: 17771
20
told you get a ssl based vpn server on your home machine, say openvpn.

【在 n*w 的大作中提到】
: 好像只有80和https可以出去。以前试过"connect.c"+ssh但是还是出不去。
n*******d
发帖数: 650
21
真正的解决方法是 pdanet+sero-sprint , 哈哈
a*****s
发帖数: 6260
22
有道理. 可能一天会有N个员工来问为什么把这个那个网站给BLOCK了...

会用

【在 z**r 的大作中提到】
: 俺知道websense可以block IP,俺的意思是,没这个必要,每个产品都有特色,干自己
: 专长的比较好,另外,俺质疑这种block all unknown IP的policy是不是真的有公司会用

1 (共1页)
进入EmergingNetworking版参与讨论
相关主题
如果你的大陆亲友不能上mitbbs,请向他们推荐aplusproxy求一个可用的HTTP代理
说个题外话, 版主进来。blocking skype
Python下载总是断掉怎么办?Ethernet MAC and IP address
WI-FI Proxy (转载)现在virtulization似乎很火啊
need a proxy (http)The next broadband killer: advanced operating systems?
Juniper/NetScreen 5GT-WLAN for homeppstream 点播功能是怎么实现p2p的?
怎么绕过proxy,看IP请教ASA5510 配置
J家的Virtual FW貌似很给力从公司remote家里电脑
相关话题的讨论汇总
话题: websense话题: ip话题: block话题: addresses话题: proxy