Blocking Kazaa 2.0?
coder_ asks: "Has anyone had success blocking the latest versions of this annoying P2P application in a network-wide context? Previously, people have been told to block a specific port, etc, yet as expected, Kazaa has found an easy solution to this. Apparently, when a connection via default port is not available, Kazaa makes encrypted http requests through port 80, making it rather difficult to now block. If anyone has had success in doing so, I would love to hear from you."
Three suggestions:
NOTE: I am not a SysAdmin, but these options are from a layman's POV.
I just set up a NAT box for a room full of students with their own laptops. I cant control the software on them, but I can control the network. I let through webproxy and ssh ports, which is all they can really ask for in order to do their work.
But the traffic is large and constant. Are they streaming radio, Kazaa'ing? I dont know. But they do want IMAP access to mailservers - doing SSH to a unix box and running 'pine' isn't enough for them - they want clicky clicky. So here's the deal. If that constant traffic goes, and it just looks like you are browsing, I'll enable IMAP access. Streaming traffic disappears.
All I need do is keep an eye on the packet counts. And save a stick for later - they're bound to want to use our printers at thesis-delivery time...