This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Blocking Teamviewer

Hello people,

I want to suppress traffic from (and to) servers run by Teamviewer (http://www.teamviewer.com). It's a remote application somewhat similar to VNC.

With Teamviewer Clients will have to open up their client-app first. This app registers with one of several Teamviewer-Servers, trying with Port 5938 first, then 80 and Port 443:

https://www.teamviewer.com/en/help/334-Which-ports-are-used-by-TeamViewer

So even when I block it's main port (5938) it still works with Port 80 only. I tried to acquire the IP range list of Teamviewers Servers through their support, so I can block those - but the support told me the Servers change often and the pool of servers grows daily.

I'm out idea how I could block this application completly. Right now running VPN for us is basicly "useless" since everyone and anyone can bypass it by using Teamviewer to connect to any machine here in my company.

Any Ideas?

edit: blocking the application through Sophos Endpoint Security could work, but it would be a hazzle to go through all kinds of Teamviewers executables (all langues, full installers, quick supports etc.) to get all those hashes.


This thread was automatically locked due to age.
Parents
  • You can use Application Control to block all Teamviewer traffic or you can make a traffic selector in QoS that limits the amount of Teamviewer traffic.  You can do the same for VNC.  Note that this does not affect traffic inside the subnet as that traffic doesn't transit the UTM (I know that you know that, but others that see this might not).

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • You can use Application Control to block all Teamviewer traffic or you can make a traffic selector in QoS that limits the amount of Teamviewer traffic.  You can do the same for VNC.  Note that this does not affect traffic inside the subnet as that traffic doesn't transit the UTM (I know that you know that, but others that see this might not).

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data