How to block anydesk or non cisco vpn services?

AlanLee
New here

How to block anydesk or non cisco vpn services?

How to block anydesk or non cisco vpn services?

 

10 Replies 10
alemabrahao
Kind of a big deal
Kind of a big deal

The most effective way I see to block the application is via the Machine's Firewall.

If you have Trellix or any other corporate firewall that users do not have access to, you can block the application without any difficulty.

I hope I have helped you.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
DarrenOC
Kind of a big deal
Kind of a big deal

As already eluded to - on the endpoint itself via something like MS Defender 

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
PhilipDAth
Kind of a big deal
Kind of a big deal

I have not tested it, but I bet if you block all access to their DNS domains, you might have a shot.

*.net.anydesk.com

*.anydesk.com

 

With anyluck, this will prevent the agents from being able to "login".

alemabrahao
Kind of a big deal
Kind of a big deal

I've tested it and it isn't effective.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
PhilipDAth
Kind of a big deal
Kind of a big deal

The next thing I would try is to do a packet capture of port 53 and then start it up, and see if it touches any other DNS entries.

 

Also, watch out for it using hard-coded DNS servers.  I think it can use 1.1.1.1 and 8.8.8.8 if the normal DNS resolver does not work.  Access for clients to external DNS servers might need to be blocked.

alemabrahao
Kind of a big deal
Kind of a big deal

The most effective way is blocking via the machine firewall.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
JamesT91
Head in the Cloud
Head in the Cloud

What if you're not in control of the endpoint and want to block any unauthorised AnyDesk usage on your network?

alemabrahao
Kind of a big deal
Kind of a big deal

So you need something like Zscaler; MX by itself can't handle it.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
PhilipDAth
Kind of a big deal
Kind of a big deal

Keep it in the family.  🙂

 

Cisco Umbrella could do it.

cmr
Kind of a big deal
Kind of a big deal

Use Cloudflare Zero Trust.  It reliably breaks AnyDesk regardless of configuration 😉

If my answer solves your problem please click Accept as Solution so others can benefit from it.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco ID. If you don't yet have a Cisco ID, you can sign up.
Labels