Solved

completely block TeamViewer For FortiGate

Posted on 2016-09-25
5
665 Views
Last Modified: 2016-10-15
Hi.....
I need to completely block team access from outside to internal clients. I need to make sure in my network that no on uses team viewer in my network

i have Fortigate 300D
0
Comment
Question by:Mansour
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 78

Assisted Solution

by:arnold
arnold earned 100 total points (awarded by participants)
ID: 41815455
Identify their IP range, and block outgoing traffic to that destination.

Adding the destination with a log event....

A simpler option in an AD environment, setup a software restriction GPO blocking the running of teamviewr.exe.
Note it will not prevent a determined individual from adjusting the application name, runn.........
0
 
LVL 70

Assisted Solution

by:Qlemo
Qlemo earned 100 total points (awarded by participants)
ID: 41815516
Blocking all IPs is hard to do, there are a lot of TeamViewer servers ...
Blocking the EXE itself is more promising, though easy to circumvent.
Anything else requires to analyze the traffic - very difficult, in particular with SSL.
0
 
LVL 27

Assisted Solution

by:Dr. Klahn
Dr. Klahn earned 100 total points (awarded by participants)
ID: 41815517
This page has a detailed explanation of one user's approach, which also short-circuits TeamViewer's fallback strategy of tunneling using port 80.

https://mediarealm.com.au/articles/2014/10/block-teamviewer-network/

However, as Qlemo points out above, if the application now tries to circumvent DNS blocking by using servers outside the teamviewer.com domain, it will probably be necessary to block the executable and hope none of your users are smart enough to rename it.
0
 
LVL 10

Accepted Solution

by:
Muhammad Mulla earned 200 total points (awarded by participants)
ID: 41816318
Under Application Control on your Fortigate, you will find 3 different signatures for TeamViewer in the Remote.Access category.

Block all of them under application overrides.
0
 
LVL 27

Expert Comment

by:Dr. Klahn
ID: 41844848
EE email requested stale question closure.
0

Featured Post

Enroll in May's Course of the Month

May’s Course of the Month is now available! Experts Exchange’s Premium Members and Team Accounts have access to a complimentary course each month as part of their membership—an extra way to increase training and boost professional development.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article covers how to install the Microsoft Windows Operating System (OS). What is covered in this article:  > Different Versions and Editions of the Windows OS  > Upgrading versus Fresh Installation of the OS           - Steps to take pr…
This article describes how to set permissions to allow a limited-permissions user to start and stop a particular System Service.   It is always best to give users only the permissions that they need to perform their job, so tweaking particular permi…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question