Topic: Router level P2P control

Offline mattnz

  • Hero Member
  • mattnz is working their way up.mattnz is working their way up.mattnz is working their way up.
  • Posts: 10,004
So what sort of hardware do I need to block P2P traffic as completely as possible? i.e. more than blocking ports, putting the brakes on people downloading crazy data.

It's in a motel situation, and I need to do work, whereas the proprietors are concerned about copyright infringement. I have the technical skills to be able to set a system up, but I'm no network engineer, so would appreciate any input.

Posted: January 10, 2013, 08:45:46 pm
Now that you have read this, plz give me neg rep :>

Offline Lias

  • Administrator
  • Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!
  • Posts: 3,975
Quote from: mattnz;1514128
So what sort of hardware do I need to block P2P traffic as completely as possible? i.e. more than blocking ports, putting the brakes on people downloading crazy data.

It's in a motel situation, and I need to do work, whereas the proprietors are concerned about copyright infringement. I have the technical skills to be able to set a system up, but I'm no network engineer, so would appreciate any input.

Not strictly speaking my area of expertise, but the short answer is WAY more than they are going to want to spend.

The much cheaper option is buy something like a Zenbu router,  and give out free access vouchers to customers.

Reply #1 Posted: January 10, 2013, 10:12:33 pm

Codex

  • Guest
Or you could put a smoothwall or other firewall pc or even install it on a rasppi and place it between the router and wan link/internet link.

Reply #2 Posted: January 10, 2013, 10:44:11 pm

Offline Spigalau

  • Hero Member
  • Spigalau is a force to reckon with.Spigalau is a force to reckon with.Spigalau is a force to reckon with.Spigalau is a force to reckon with.Spigalau is a force to reckon with.Spigalau is a force to reckon with.Spigalau is a force to reckon with.Spigalau is a force to reckon with.
  • Posts: 10,736
Matt - 'Untangle' appliance.

http://www.untangle.com/

Have one @ work for Network QOS and it's a no brainer. The Application Control module should do what you want.

Reply #3 Posted: January 11, 2013, 07:10:47 am
49 20 63 61 6e 20 72 65 6d 65 6d 62 65 72 20 77 68 65 6e 20 74 68 65 20 61 69 72 20 77 61 73 20 63 6c 65 61 6e 20 61 6e 64 20 73 65 78 20 77 61 73 20 64 69 72 74 79 2e

Codex

  • Guest
^They look pretty awesome

Reply #4 Posted: January 11, 2013, 07:55:56 am

Offline mattnz

  • Hero Member
  • mattnz is working their way up.mattnz is working their way up.mattnz is working their way up.
  • Posts: 10,004
Yeah, thought it might be a bit expensive/technical. Ah well, just gives me an excuse not to work, thanks :D

Reply #5 Posted: January 11, 2013, 12:32:48 pm
Now that you have read this, plz give me neg rep :>

Offline Lias

  • Administrator
  • Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!
  • Posts: 3,975
Quote from: Codex;1514145
Or you could put a smoothwall or other firewall pc or even install it on a rasppi and place it between the router and wan link/internet link.


The Problem:
It is simply not possible to rely on port numbers in order to determine what applications are running on a network. Standard applications can run on non-standard ports, malicious or bandwidth hungry applications can run on random ports or standard ports pretending to be another application, and some applications spawn child connections on random ports. Making network infrastructure decisions or enforcing Quality of Service becomes impossible without knowing exactly what’s running on the network.

Exinda Layer 7 Discovery:
Exinda uses L7 signatures in conjunction with advanced pattern matching technology and proprietary connection analysis technology to discover applications at layer 7. The L7 discovery system provides the following benefits.
  • Discovery of applications running on non-standard ports (e.g. HTTP over ports other than 80).
  • Discovery of applications using seemingly random ports (e.g. P2P).
  • Discovery of applications pretending to be another application by deliberately using standard ports (e.g. P2P, steaming, IM over HTTP, port 80).
  • Discovery of applications that spawn child connections on random ports (e.g. FTP, SIP).
  • Discovery of applications that are fully encrypted like BitTorrent and Skype


Blocking ports will stop some traffic, not Matt's post said he wanted something that goes beyond that.. Something like an Exinda appliance.. and they are 5-6 figures.

Reply #6 Posted: January 12, 2013, 10:50:01 am

Offline zolteg

  • Devoted Member
  • zolteg has no influence.
  • Posts: 1,931
Or you could look at http://www.clearfoundation.com/Software/overview.html  , which offers a layer 7 filter, is very usable, and appears to be free.....

Reply #7 Posted: January 13, 2013, 02:56:32 pm