There is a program called socks 2 http made by totalrc.net that can funnel socks requests through a http proxy. I so far, can not figure out how to block this application. I have been testing with version 0.3 of socks 2 http. It runs on the client and they enter the http proxy settings into socks 2 http. They then list the socks proxy in the application(kazaa or what ever) as localhost(127.0.0.1) Currently the only proxy enabled on ASL is the http proxy. The packet filter is set to any any any drop. The only service that socks 2 http seems to need is http. I removed everything but that and it still works. This has become extremely annoying as our users are wasting time and resources with there abuse of this system.
Thanks
This thread was automatically locked due to age.