- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Anyone have a slick way to block all Remote Access Tools?
I was hoping to find a Content category that would block remote access tools (gotomypc, logmein, etc) but didn't find one. Anyone have a good way to setup a generic block to these types of connections?
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I don't believe there is an easy way. I would personally search for all known ports used by remote access tools and block them.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Many of these tools have an automatic fallback to TCP/80, TCP/443 or even HTTP/S. This will likely not work.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you try blocking all remote monitoring & management?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Anyone have an update on this...checking talos on this most of the remote desktop tools are categorized as online meetings. So teamviewer/anydesk is categorized the same as Teams...which fundamentally makes no sense.
Curious if this has evolved?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you not Deny at Layer 7 as below:
And add L3 Deny rules for teamviewer.com etc provided the MX has seen the DNS lookup, or if using internal DNS setup a teamviewer.com domain and resolve to 127.0.0.1 ??
