There are always new posts regarding problem connecting in Yahoo IM , MSN Messenger, Kazza, iMesh client and other softwares. Here are some tips, always follow them before posting new posts at forum. May be these hints will help you.
HTTP Redirector setting solves many problem initally. Set HTTP Filter to "Send to requested web server." because some softwares,apps requires direct connection with the net and no proxy between. they need to bypass the web proxy.
Voice and video works only if you connect with no proxy settings, bcoz if you specify any proxy or socks setting, you will be able to text chat only. Voice n Vdo require direct connection with the opponent user.
Remove authentication for test purpose. Many apps donot have the ability to handshake with the NTLM authentication.
MSN Messenger / Chat / Voice n Video : ======================================
Msn messenger port = 1863 Servers = messenger.msn.com / gateway.messenger.com It uses port 1863 by default. If you have trouble connecting messenger with default "no proxy" setting,You can also configure it to use port 80 or socks 4.
MSN Vocie and video donot work with ISA, because it donot support uPNP protocol. Some time it works or some time it don't. If other person connected directly to iNternet sends you request for voice conversation then it may work, but it's not always work.
Yahoo Messenger / Chat / Voice n Video : ========================================
Yahoo Messenger Port = 5050
Yahoo uses 5050 to Messenger servers,If you wish to know what ports Messenger uses, this is the order in which Messenger scans:
5050 80 All available
In order to use all the Yahoo! Messenger Webcam features, your firewall must permit incoming and outgoing TCP connections on port 5100 If yahoo IM donot connect, point it to use http proxy or socks 4.
Kazaa, iMesh Client : =====================
Kazaa Port : 1214 / TCP / Outbond iMesh : 6699 / TCP / Oubond New version of KAZAA uses smart technology and port 80 if default ports are blocked or not available. so no extra config is required. only FWC is required OFFCOURSE. :>
These are the servers listing, which yahoo messenger uses for different services, you can block these ports OR you can make an deny rule in S&C to block these destination.
This is great information, thanks for the work. While reading your wealth of information I did have a thought that I thought I'd get an opinion on. Let's say you want to block an instant messenger from being used, the workstations are set up as Proxy Clients with the Firewall client installed and the HTTP Redirector disabled, couldn't you place the name of application to be blocked in the Firewall Client Properties, set to Disabled with a value of "1"? Wouldn't that prevent that client from getting out? CouldnĘt this be used to block about any Winsock application?
According to Tom's article regarding 'Howto block dangerous applications" using FWC apps name, it never worked for me. If this works, it will be very good. Like I want to block kazaa which is an ongoing problem for all network admins, as it sucks the whole bandwith pipe, i create app name kazaa.exe and set it value to disable=1, at client i updated mspclnt, but it didn't work out. Check for yourself, and see if it works,
I guarantee that it works. But the clients must be configured as Firewall clients ONLY. If they are configured as SecureNAT clients, by can access the mspclnt.ini settings.
RE: Tips for msn,yahoo,kazaa - 24.Oct.2003 10:46:00 PM
Guest
Hi Syed, I see you mentioned adding "kazaa.exe" to the FWC list. Add "kazaa" without the ".exe" and the blocking should work fine. I've been blocking it successfully using this method. Ofcourse some people act "smart" and change the name of the executable... well for that (since I believe you run a cablenet service) I would suggest that you block all net access for those customers that don't behave. I've found it to be the most effective method to stop bandwidth abuse.
My own method has been to allow only those ports which are deemed necessary on the network. I currently have all major apps running perfectly with voice and webcam capabilities, while blocking all P2P apps.
i want o know how did we set this settings in ISA server and wat abt msn6 this thing realy makes my user fadup and me terribly worried msn6 is not working well althoug i hv an individual firewall server give me the tip for msn6 thanks
hi i want to know the direction of ports is it inbound or outbound and one more thing how to set these servers on isa from where should i set all these servers for webcam voice and others
Audio Conversation for MSN MESSENGER via ISA: Additionally to your comment to open TCP port 1863, there is more information in Microsoft Knowledge Base Article - 284554 (How to: Add Support for MSN Messenger Net2Phone in Internet Security and Acceleration server 2000). I tried the steps described in this article to achieve audio conversation; I opened the Primary Connection TCP 1863 outbound, and the Secondary Connections UDP 5004-65535 Send Receive, TCP 6891-6900 Inbound, TCP 6891-6900 Outbound, and TCP 6901 Outbound. Further I updated the Firewall Client with [msmsgs]; NameResolutionForLocalHost=E; RemoteBindUdpPorts=0,6901. Now the MSN Messenger recognices that it is connected to the ISA server as shown in the MSN Messenger TOOLS - OPTIONS - CONNECTION - Advanced Connection Information. However, still the Audio Connection does not work in both directions. Also, with reference to Microsoft Knowledge Base Article - 278887, MSN Messenger shall work with Voice Connections via Proxy Server (e.g., ISA). Please share with me experience, to configure ISA for MSN Messenger, Voice or Audio Connections. best regards Martin