How to drop or block Skype connections with your gateway firewall

Written by Gionatan Danti on . Posted in Howto

User Rating:  / 19
PoorBest 

Skype hosts list

So, in many circumstances where UTM-device are not available, the best approach is to deny all traffic to Skype hosts. So, what are the IP addresses used to authenticate? The hosts I found are included in the following networks:

  • 111.221.74.0/24
  • 111.221.77.0/24
  • 157.55.130.0/24
  • 157.55.235.0/24
  • 157.55.56.0/24
  • 157.56.52.0/24
  • 194.165.188.0/24
  • 195.46.253.0/24
  • 213.199.179.0/24
  • 63.245.217.0/24
  • 64.4.23.0/24
  • 65.55.223.0/24

Please note that, while I masked all network with a C subnet (/24), the real subnet mask can be quite different (ie: it can be a smaller /28 netmask). However, any false positive should be easily detectable by simply enabling connections logging on your firewall.

For a complete connections log of my Skype login attempt, you can download this file.

A blocked Skype login attempt

A blocked Skype login attempt

Sure, a new Skype version and/or upgrade can boast a new hosts list, but this approach should work in a number of cases: I tested both Skype beta 2.2 for Linux and Skype 5.9 for Windows XP, and both were blocked by my gateway firewall.

Comments   

 
#1 Akiv 2013-07-23 14:24
This was very helpful. I had to add some more ip ranges tracked through firewall. So far seems good.
 
 
#2 Gionatan Danti 2013-07-23 14:41
I'm glad to know that my suggestion worked for you :)

If you want, you can suggest us (via this comment system) the additional tracked IP ranges.

Thanks.
 
 
#3 Daniel 2013-10-14 21:42
This article here summarizes and quickly explains (what this article explains in detail)

Scroll to the bottom of the first page for instructions on how to do this!

http://forums.anandtech.com/showpost.php?p=35604779&postcount=11
 
 
#4 Yvonne 2015-05-22 15:27
Appreciate presenting this to everyone.
 
 
#5 Randy 2016-05-04 23:57
How do I block mobile devices from using Skype? This method only works for laptops and desktops. My iPhone and iPad with the Skype App works with this in effect.
 

You have no rights to post comments