This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Blocking Teamviewer

Hello people,

I want to suppress traffic from (and to) servers run by Teamviewer (http://www.teamviewer.com). It's a remote application somewhat similar to VNC.

With Teamviewer Clients will have to open up their client-app first. This app registers with one of several Teamviewer-Servers, trying with Port 5938 first, then 80 and Port 443:

https://www.teamviewer.com/en/help/334-Which-ports-are-used-by-TeamViewer

So even when I block it's main port (5938) it still works with Port 80 only. I tried to acquire the IP range list of Teamviewers Servers through their support, so I can block those - but the support told me the Servers change often and the pool of servers grows daily.

I'm out idea how I could block this application completly. Right now running VPN for us is basicly "useless" since everyone and anyone can bypass it by using Teamviewer to connect to any machine here in my company.

Any Ideas?

edit: blocking the application through Sophos Endpoint Security could work, but it would be a hazzle to go through all kinds of Teamviewers executables (all langues, full installers, quick supports etc.) to get all those hashes.


This thread was automatically locked due to age.
Parents
  • Hi,

    I used the flow monitor to create a rule named "TeamViewer blocked via Flow Monitor"

    Unfortunately this doesn't block it. I have no exceptions nor Application Control Skiplist...

    The Flow Monitor only detects a little bit of traffic sometimes, as you can see here:

    We are using TeamViewer 10. All internet traffic passes the UTM9.

  • I haven't used the Flow Monitor to make AppCtrl rules, Stefan.  What happens if you manually create a rule below that one that allows and logs TeamViewer traffic - does it see the traffic?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob,


    The first thing I did was creating the block rule manually. It looked the same, and did the exact same thing, nothing...

    I also created an allow & log rule, but it doens't see any traffic in live log...

Reply Children
No Data