KB Article | Forcepoint Support

Problem Description

I am using Next Generation Firewall (NGFW) and I want to block Skype for my company.

Resolution

When you download Skype application, the executable file contains a list of IP addresses (Skype refers to these IP address as "super nodes" - Skype clients that have a public IP address) that the Skype application tries to connect to. The Skype application can automatically connect to a Skype peer-to-peer architecture through any open Transmission Control Protocol (TCP) port higher than 1024, or ports 80 and 443. If your company restricts outbound connections to ports higher than 1024, the Skype application will try to connect through ports 443 and 80.

The Skype application mostly uses User Datagram Protocol (UDP) for calls and TCP for messages, however the application may use either UDP or TCP for both calls and messages if there is no connectivity (for example, if UDP traffic is blocked). All messages that Skype sends are encrypted and are intended to select IP addresses at random.

The following best practices for blocking Skype apply to Next Generation Firewall (NGFW) versions 5.x to 6.x:

The Skype application element in Security Management Center can only detect traffic sent by Skype on ports 80 and 443. The application cannot entirely block Skype because it cannot be reliably detected when running on other ports.

The Skype Servers group was added in dynamic update 636; this includes the IP ranges covering all known Skype super nodes.

Note This group is actively updated in new update packages, so Forcepoint recommends you activate the latest package.

To prevent Skype usage and all login methods:
  • Discard all connections (Service: ANY) where destination is the Skype Servers group. This will block all of those connections to Skype Servers.
  • Discard connections to all destinations where service is the Skype application. This block all HTTP and HTTPS connections from Skype to any other servers.
Note HTTPS decryption is not required.

Article Feedback



Thank you for the feedback and comments.