Microsoft KB Archive/932486

= How to configure Internet Security and Acceleration (ISA) Server 2000 to block Windows Live Messenger traffic =

Article ID: 932486

Article Last Modified on 2/15/2007

-

APPLIES TO


 * Microsoft Internet Security and Acceleration Server 2000 Standard Edition

-



INTRODUCTION
This article describes how to configure Microsoft Internet Security and Acceleration (ISA) Server 2000 to block Windows Live Messenger traffic.



MORE INFORMATION
In later versions of ISA Server such as Microsoft Internet Security and Acceleration (ISA) Server 2004 or Microsoft Internet Security and Acceleration (ISA) Server 2006, you can use Request headers or Response headers to block Windows Live Messenger traffic. However, this functionality is not available in ISA Server 2000. To block Windows Live Messenger traffic in ISA Server 2000, follow these steps:  Start the ISA Management tool. Create a destination set that includes Windows Live Messenger destinations. To do this, follow these steps:  Expand Servers and Arrays, expand the particular server or array in which you want to create the destination set, expand Policy Elements, and then click Destination Sets. On the Action menu, point to New, and then click Destination Set. In the Name box, type a descriptive name such as Live Messenger Destinations . Click Add, leave the default Destination option selected, type *.live.com in the Destination box, and then click OK. Click Add, click IP addresses, type 207.46.108.35 in the From box, and then click OK two times.</li></ol> </li> Create a content group that contains the following three content types: <ul> application/x-msn-messenger</li> text/x-msmsgsprofile</li> text/x-msmsgsinitialmdatanotification</li></ul>

To do this, follow these steps: <ol style="list-style-type: lower-alpha;"> Under Policy Elements, click Content Groups.</li> On the Action menu, point to New, and then click Content Group.</li> In the Name box, type a descriptive name such as Live Messenger Content .</li> In the Available types list, type application/x-msn-messenger, and then click Add.</li> In the Available types list, type text/x-msmsgsprofile, and then click Add.</li> In the Available types list, type text/x-msmsgsinitialmdatanotification, and then click Add.</li> Click OK.</li></ol> </li> Create a protocol rule to deny the MSN Messenger protocol. This rule should deny outgoing requests on port 1863. To do this, follow these steps: <ol style="list-style-type: lower-alpha;"> Expand Access Policy, and then click Protocol Rules.</li> On the Action menu, point to New, and then click Rule.</li> In the Protocol rule name box, type a descriptive name, and then click Next.</li> Click Deny, click Next, and then click Selected protocols in the Apply this rule to list.</li> <li>In the Protocols list, click to select the MSN Messenger check box, and then click Next.</li> <li>Leave the Always option selected in the Use this schedule list, and then click Next.</li> <li>Leave the Any request option selected, click Next, and then click Finish.</li></ol> </li> <li>Create a site and content rule to deny the Windows Live Messenger destination set. To do this, follow these steps: <ol style="list-style-type: lower-alpha;"> <li>Under Access Policy, click Site and Content Rules.</li> <li>On the Action menu, point to New, and then click Rule.</li> <li>In the Site and content rule name box, type a descriptive name for the rule, and then click Next.</li> <li>Click Deny, click Next, click Deny access based on destination, click Next, and then click Specified destination set in the Apply this rule to list.</li> <li>In the Name list, click Live Messenger Destinations.

Note If you used a different name when you created the Windows Live Messenger destination set in step 2, click that name in the Name list.</li> <li>Click Next, and then click Finish.</li></ol> </li> <li>Create a site and content rule to deny the Windows Live Messenger content group. To do this, follow these steps: <ol style="list-style-type: lower-alpha;"> <li>Under Access Policy, click Site and Content Rules.</li> <li>On the Action menu, point to New, and then click Rule.</li> <li>In the Site and content rule name box, type a descriptive name for the rule, and then click Next.</li> <li>Click Deny, click Next, click Custom, click Next, click All destinations in the Apply this rule to list, and then click Next.</li> <li>In the Use this schedule list, click Always, and then click Next.</li> <li>Click Any request, click Next, and then click Only the following content types.</li> <li>In the Content type list, click to select the Live Messenger Content check box.

Note If you used a different name for the Windows Live Messenger content group that you created in step 3, click to select the check box that corresponds to the appropriate content group.</li> <li>Click Next, and then click Finish.</li></ol> </li></ol>

For more information about how to use ISA Server 2004 or ISA Server 2006 to block Windows Live Messenger traffic, click the following article number to view the article in the Microsoft Knowledge Base:

925120 How to block MSN Messenger traffic and Windows Live Messenger traffic by using ISA Server

Keywords: kbfirewall kbhowto kbinfo KB932486

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.