Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
How to block network discovery?
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
rado3105
Apprentice
Apprentice


Joined: 14 Jul 2007
Posts: 293

PostPosted: Sat Jan 02, 2010 10:00 pm    Post subject: How to block network discovery? Reply with quote

Is possible to block network discovery? I dont want from people on my network to see each other(using various programs...) or to know architecture of network....

Last edited by rado3105 on Sat Jan 02, 2010 10:14 pm; edited 1 time in total
Back to top
View user's profile Send private message
Hu
Administrator
Administrator


Joined: 06 Mar 2007
Posts: 23066

PostPosted: Sat Jan 02, 2010 10:14 pm    Post subject: Reply with quote

Yes. Configure your switch to disallow passing traffic on the relevant discovery protocols.
Back to top
View user's profile Send private message
rado3105
Apprentice
Apprentice


Joined: 14 Jul 2007
Posts: 293

PostPosted: Sat Jan 02, 2010 10:16 pm    Post subject: Reply with quote

so there is enough to block udp port 1900? or any other?
Back to top
View user's profile Send private message
Inodoro_Pereyra
Advocate
Advocate


Joined: 03 Nov 2006
Posts: 2631
Location: En la otra punta del cable

PostPosted: Sat Jan 02, 2010 10:17 pm    Post subject: Reply with quote

And by network discovery you are talking of...?

You can block uPNP, SSDP, SNMP Netbios broadcasts and any other protocol you can think on using firewalls o routing between hosts but you can't block ARP traffic for example, or your box will be isolated from the net.

A little more info would be useful.

Cheers!
_________________
Mi Blog.

Si no fuera por C, estaríamos escribiendo programas en BASI, PASAL y OBOL.
Back to top
View user's profile Send private message
rado3105
Apprentice
Apprentice


Joined: 14 Jul 2007
Posts: 293

PostPosted: Sat Jan 02, 2010 10:22 pm    Post subject: Reply with quote

I want to disable discovery samba(but not if client has specific ip, just discovery), discovery network(and computers on network - using various tools like mikrotik dude..), and what is recomended. I dont want block services, just discovering ....of services using various tools..
Back to top
View user's profile Send private message
Bircoph
Retired Dev
Retired Dev


Joined: 27 Jun 2008
Posts: 261
Location: Moscow

PostPosted: Sun Jan 03, 2010 6:44 am    Post subject: Reply with quote

Inodoro_Pereyra wrote:
but you can't block ARP traffic for example, or your box will be isolated from the net.

But you may filter it, e.g. to remove local replies from local hosts to non-servers. Ebtables may be usefull here.
_________________
Per aspera ad astra!
Back to top
View user's profile Send private message
rado3105
Apprentice
Apprentice


Joined: 14 Jul 2007
Posts: 293

PostPosted: Sun Jan 03, 2010 9:21 am    Post subject: Reply with quote

Just part of network is bridged, all connections goes through routers, so I dont need ebtables. Just need to know what is good to block(what ports, I just found 1900udp port).
Back to top
View user's profile Send private message
Hu
Administrator
Administrator


Joined: 06 Mar 2007
Posts: 23066

PostPosted: Sun Jan 03, 2010 5:38 pm    Post subject: Reply with quote

What do you hope to accomplish by this blocking?
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum