Best Technology Articles

IT Tips, Networking Articles, Networking Tutorials, Programming Tutorials, ASP Tutorials, PhP Tutorials, ADS Installation, Network Setup, Networking Tips and Tricks, Hacking Articles, Software Tips, Macintosh Articles, Macintosh Tips, Technology Tips, Mobile Softwares, Mobiles Rates in Pakistan

Messenger Blocking:

Many people complains that their employees don’t do enough work rather they would sign in to their msn messengers and start chatting early in the morning, in the lunch break and whenever they find time. This prevents them from doing work, they become lazy and the workload increases. In this article I will show you step by step in blocking msn messenger to be signed in from your network.

To block the use of msn messenger

Follow these steps to accomplish this task

You have to modify the default Site and Content Rule, Protocol Rule and the Firewall Client properties to block the use of msn messenger.

1. Open the ISA Management console, expand your ISA server computer and click on Client Configuration.

How to Block the use of MSN Messenger in ISA Server 2000

2. In the details pane, right click Firewall Client and click Properties.

How to Block the use of MSN Messenger in ISA Server 2000_files

3. Click on the Application Settings tab.

How to Block the use of MSN Messenger in ISA Server 2000_files

4. Click on NEW and on the Application text box type msnmsgr. On the Key drop down menu select Disable and on the Value text box type 1.

How to Block the use of MSN Messenger in ISA Server 2000_files

5. Click on OK twice.

6. Update your firewall clients by clicking on Update on the Firewall Client on your client computers. The default update time for firewall client is 6 hours.

How to Block the use of MSN Messenger in ISA Server 2000_files

7. Expand Policy Elements, right click Destination Sets and click on New Set.

How to Block the use of MSN Messenger in ISA Server 2000_files

8. Type a friendly name in the Name text box and click Add.

How to Block the use of MSN Messenger in ISA Server 2000_files

9. Type *.msgr.hotmail.com in the Destination text box and click OK.

How to Block the use of MSN Messenger in ISA Server 2000_files

10. Click on OK.

11. Expand Access Policy and click on Site and Content Rule.

How to Block the use of MSN Messenger in ISA Server 2000_files

12. In the details pane, double click on the default Site and Content Rule and click on the Destinations tab. The default rule Allows everyone.

How to Block the use of MSN Messenger in ISA Server 2000_files

13. Under This rule applies to select All destinations except selected set and from the Name drop down menu select the destination set that we created.

How to Block the use of MSN Messenger in ISA Server 2000_files

14. Click Apply and then click OK.

15. Under Access Policy click on the Protocol Rules.

How to Block the use of MSN Messenger in ISA Server 2000_files

16. In the details pane double click the protocol rule. Click on the Protocol tab.

How to Block the use of MSN Messenger in ISA Server 2000_files

17. Under This rule applies to select All IP traffic except selected.

18. Select the MSN and MSN Messengers check boxes.

How to Block the use of MSN Messenger in ISA Server 2000_files

19. Click Apply and then click OK.

INTRODUCTION

This article describes how to configure Microsoft Internet Security and Acceleration (ISA) Server 2000 to block Windows Live Messenger traffic.

MORE INFORMATION

In later versions of ISA Server such as Microsoft Internet Security and Acceleration (ISA) Server 2004 or Microsoft Internet Security and Acceleration (ISA) Server 2006, you can use Request headers or Response headers to block Windows Live Messenger traffic. However, this functionality is not available in ISA Server 2000. To block Windows Live Messenger traffic in ISA Server 2000, follow these steps:
1.Start the ISA Management tool.
2.Create a destination set that includes Windows Live Messenger destinations. To do this, follow these steps:
a. Expand Servers and Arrays, expand the particular server or array in which you want to create the destination set, expand Policy Elements, and then click Destination Sets.
b. On the Action menu, point to New, and then click Destination Set.
c. In the Name box, type a descriptive name such as Live Messenger Destinations.
d. Click Add, leave the default Destination option selected, type *.live.com in the Destination box, and then click OK.
e. Click Add, click IP addresses, type 207.46.108.35 in the From box, and then click OK two times.
3.Create a content group that contains the following three content types:
application/x-msn-messenger
text/x-msmsgsprofile
text/x-msmsgsinitialmdatanotification
To do this, follow these steps:
a. Under Policy Elements, click Content Groups.
b. On the Action menu, point to New, and then click Content Group.
c. In the Name box, type a descriptive name such as Live Messenger Content.
d. In the Available types list, type application/x-msn-messenger, and then click Add.
e. In the Available types list, type text/x-msmsgsprofile, and then click Add.
f. In the Available types list, type text/x-msmsgsinitialmdatanotification, and then click Add.
g. Click OK.
4.Create a protocol rule to deny the MSN Messenger protocol. This rule should deny outgoing requests on port 1863. To do this, follow these steps:
a. Expand Access Policy, and then click Protocol Rules.
b. On the Action menu, point to New, and then click Rule.
c. In the Protocol rule name box, type a descriptive name, and then click Next.
d. Click Deny, click Next, and then click Selected protocols in the Apply this rule to list.
e. In the Protocols list, click to select the MSN Messenger check box, and then click Next.
f. Leave the Always option selected in the Use this schedule list, and then click Next.
g. Leave the Any request option selected, click Next, and then click Finish.
5. Create a site and content rule to deny the Windows Live Messenger destination set. To do this, follow these steps:
a. Under Access Policy, click Site and Content Rules.
b. On the Action menu, point to New, and then click Rule.
c. In the Site and content rule name box, type a descriptive name for the rule, and then click Next.
d. Click Deny, click Next, click Deny access based on destination, click Next, and then click Specified destination set in the Apply this rule to list.
e. In the Name list, click Live Messenger Destinations.

Note If you used a different name when you created the Windows Live Messenger destination set in step 2, click that name in the Name list.
f. Click Next, and then click Finish.
6. Create a site and content rule to deny the Windows Live Messenger content group. To do this, follow these steps:
a. Under Access Policy, click Site and Content Rules.
b. On the Action menu, point to New, and then click Rule.
c. In the Site and content rule name box, type a descriptive name for the rule, and then click Next.
d. Click Deny, click Next, click Custom, click Next, click All destinations in the Apply this rule to list, and then click Next.
e. In the Use this schedule list, click Always, and then click Next.
f. Click Any request, click Next, and then click Only the following content types.
g. In the Content type list, click to select the Live Messenger Content check box.

Note If you used a different name for the Windows Live Messenger content group that you created in step 3, click to select the check box that corresponds to the appropriate content group.
h. Click Next, and then click Finish.