Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

completely block TeamViewer For FortiGate

Posted on 2016-09-25
5
Medium Priority
?
1,673 Views
Last Modified: 2016-10-15
Hi.....
I need to completely block team access from outside to internal clients. I need to make sure in my network that no on uses team viewer in my network

i have Fortigate 300D
0
Comment
Question by:Mansour
5 Comments
 
LVL 80

Assisted Solution

by:arnold
arnold earned 400 total points (awarded by participants)
ID: 41815455
Identify their IP range, and block outgoing traffic to that destination.

Adding the destination with a log event....

A simpler option in an AD environment, setup a software restriction GPO blocking the running of teamviewr.exe.
Note it will not prevent a determined individual from adjusting the application name, runn.........
0
 
LVL 71

Assisted Solution

by:Qlemo
Qlemo earned 400 total points (awarded by participants)
ID: 41815516
Blocking all IPs is hard to do, there are a lot of TeamViewer servers ...
Blocking the EXE itself is more promising, though easy to circumvent.
Anything else requires to analyze the traffic - very difficult, in particular with SSL.
0
 
LVL 30

Assisted Solution

by:Dr. Klahn
Dr. Klahn earned 400 total points (awarded by participants)
ID: 41815517
This page has a detailed explanation of one user's approach, which also short-circuits TeamViewer's fallback strategy of tunneling using port 80.

https://mediarealm.com.au/articles/2014/10/block-teamviewer-network/

However, as Qlemo points out above, if the application now tries to circumvent DNS blocking by using servers outside the teamviewer.com domain, it will probably be necessary to block the executable and hope none of your users are smart enough to rename it.
0
 
LVL 10

Accepted Solution

by:
Muhammad Mulla earned 800 total points (awarded by participants)
ID: 41816318
Under Application Control on your Fortigate, you will find 3 different signatures for TeamViewer in the Remote.Access category.

Block all of them under application overrides.
0
 
LVL 30

Expert Comment

by:Dr. Klahn
ID: 41844848
EE email requested stale question closure.
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many admins will agree: WSUS is is a nice invention but using it on the client side when updating a newly installed computer is still time consuming as you have to do several reboots and furthermore, the procedure of installing updates, rebooting an…
At the beginning of the year, the IT world was taken hostage by the shareholders of LogMeIn. Their free product, which had been free for ten years, all of the sudden became a "pay" product. Now, I am the first person who will say that software maker…
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question