Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Intercept Teamvi through Cisco ASA inspection

Shulou Source: shulou.com Published: 2022-06-01 04:18:08 10月06日 Update

teamviewer connection process:

After running TeamViewer, the computer connects to the TV server, which assigns the computer a unique ID based on MAC.

When one TeamViewer connects to another, it connects to the server first, and finds the computer to connect to by mapping ID to computer.

1. If either party of the connection is a network environment with a public IP, the P2P connection is initiated from the intranet IP to the public IP party. At this time, the session initiation direction is trust to untrust.

2. If both parties are intranet, TeamViewer data will be transferred through TeamViewer's own server. At this time, the session initiation direction is also trust to untrust.

The security policy of only prohibiting external network to internal network is to prohibit teamviewer. teamviewer can use any of the three ports 80, 443 and 5938 to establish a connection with the transit server. Application filtering needs to be configured to prohibit teamviewer programs in the direction of trust to untrust.

regex TV-RGX ".teamviewer.com"

regex DG-RGX ".dyngate.com"

class-map type regex match-any TV-CLS

match regex DG-RGX

match regex TV-RGX

policy-map type inspect dns TV-PLC

parameters

message-length maximum 512

match domain-name regex class TV-CLS

drop

policy-map global_policy

class inspection_default

inspect dns TV-PLC

service-policy global_policy global

Tags: Server service direction computer public network transit security one side three both parties situation data time environment program port policy network process allocation Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Shulou Tech Info Shulou Information Microsoft Redmi vpn