On Jun 1, 2005, at 1:48 PM, Rog�rio Moura wrote:

Hello!!
I like to know if PF can block packets by the content (type
patch-o-magic string of IPTABLES), because my network have connections
of skype and messenger, this programs use ports that are allowed in
the firewall, type 80, 443 and I not know how block this programs!!!!

can anybody help me?

http://www.squid-cache.org

Use a proxy to "normalize" the traffic. IIRC, Skype requires UDP packets for the voice packets. Simply block udp/80 and allow tcp/80 and tcp/443 through the proxy.

HTH.

--
Jason Dixon
DixonGroup Consulting
http://www.dixongroup.net


Reply via email to