Block Torrents & p2p Traffic 100% working on all versions

this rule

add action=drop chain=forward comment=“more connection closed” disabled=no


block all traffic my network ( rb433ah , bridge mode)

is correct?

the others works properly

this rule : add action=drop chain=forward comment=“more connection closed” disabled=no

block all traffic my network (rb433ah, bridge wlan1-eth1)

is correct?

all others rules works perfect

Hey guys! I have done this, and it works pretty great for what I needed, but I have one question. Is there a way to make it redirect to a website instead of just dropping? I want to tell all customers that it is against ToS to use torrents through a web page. Thanks

The only problem I really see with this, is that it blocks things for keywords. Like me making this post, since it has the keywords in it, I have to use a different gateway to post.. Any idea for a way around that?

great! This would be very useful!

Maybe I am wrong, but the proposed solution blocks the downloads of the .torrent files (GET) from known torrent repositories. This is of course important but not effective.
But it won’t block the torrent protocol (file sharing) itself. Which is what I’d like to block, as torrent files can be exchanged via email or even through removable media.
Any idea?

this even blocks news sites if there is something mentioned about torrents.

this does not work if you use https

I just copied this from somewhere in the forum, I want to integrate it with blocking downloading of .mp3, *.mp4 etc, how will I add this to the l7-layer, is this one correct cus i dont see it catching any traffic

1./ip firewall layer7-protocol
add name=streaming2 regexp=""^.*get.+\\.(3gp|mov|mpe|mpeg|mpeg2|mpeg3|mpeg4|mkv|avi|flv|f4v|f4p|f4a
|f4b|x-flv|msi|wmv|mp2|mp3|mp4|swf|rm|rmvb|vcd|pdf|dat|iso|nrg|bin|cab|vcd|ogg|wma|divx|d2v|qt|0[0-9][0-9])

  1. /ip firewall mangle
    add action=mark-packet chain=prerouting comment=“Mark Packet Streaming” disabled=no
    layer7-protocol=streaming new-packet-mark=streaming2 passthrough=no

You can adjust the max-limit to anything higher like 128k
3. /queue tree add name=“streaming2” parent=global packet-mark=streaming2 limit-at=0 queue=default
priority=8 max-limit=48k burst-limit=0
burst-threshold=0 burst-time=0s

today there is so many ways of using torrent, because that blocking it is a never ending work

the main reason to block torrent is because use too much bandwidth

i think there is no need to block torrent i think is better to properly identify torrent and p2p traffic to give it a lower priority and control the congestion it generates and guarantee the good performance on the other applications

I agree with chechito. The only "small problem"™ is to correctly identifying the torrent traffic.
Blocking the download of the torrent file itself is useless as torrents can be added manually from other sources.
I think that only Deep Packet Inspection can help.
Any ideas?

in my case i have identified torrent traffic by discard, detecting another protocols and services usually leave me with torrent on the “unclassified” part of the traffic leaving it with low priority

Do you mean “everything else” (everything but HTTP, HTTPS, SSH, SMTPS, IMAP4S POP3S..) is considered torrent?
If so, which protocols are you considering?
If not, please elaborate.
As I cannot really block P2P in general, I am trying to throttle “everything else”.
The problem is that outgoing P2P can also go to TCP:80, TCP:443, TCP:53 and UDP:53 and so on…
In these cases throttling wouldn’t apply. And this is why I am talking about DPI.

people are using 80 and 443 and 53 or another well known ports because of the blocking, because that is better to throttle than blocking

and with throttle im referencing to give the torrent the possibility of using all the spare bandwidth not throttling it to a ridiculous speeds

Is not perfect but it works in many cases and its free

if some one need better detection of P2P is better to go with an expensive fortigate or another UTM and pay the expensive annual license fee

for example

fortigate 80d recommended for 65mbps of wan channel cost ~750US without services, and ~1.740US with 3 year service subscription that is ~330 US per year of subscription

fortigate 200d recommended for 150mbps of wan channel cost ~2.300US without services, and ~5.200US with 3 year service subscription that is ~960 US per year of subscription

fortigate 600d recommended for 1.100mbps of wan channel cost ~8.000US without services, and ~17.840US with 3 year service subscription that is ~3.280 US per year of subscription

fortigate 1500d recommended for 2.300mbps of wan channel cost ~30.000US without services, and ~66.900US with 3 year service subscription that is ~12.300 US per year of subscription

fortigate 3000d recommended for 6.000mbps of wan channel cost ~60.000US without services, and ~133.800US with 3 year service subscription that is ~24.600 US per year of subscription

So, was I right?
I mean, do you simply throttle “everything else” but a bunch of “well known useful protocols”?

yes i priorize traffic in this order:

tcp ack packets, dns, icmp, udp traffic whit characteristics matching most voip and gaming apps, vpns, rdp, http small traffic connections, http big traffic connections, mail connections, other udp tcp small traffic connections.

the remaining traffic are other tcp and udp connections with big traffic, torrent transfer get on this category

add chain=forward src-address=192.168.1.0/24 p2p=all-p2p action=drop comment=p2p_drop


not working
buz i need to drop “psiphon vpn” from server ,

how can drop that p2p buz drop vpn?

I have tried all the methods posted above and torrents still download.I am new to Mikrotik. Please help

I started by dropping all incoming TCP and UDP traffic (all of it) but those services that go to DMZ.
So there’s no traffic going to LAN, which means “low ID” in the P2P lingo.

Then I started throttling (I’d like to drop, actually) all outgoing traffic from LAN with UDP ports other than 53 (DNS) and 123 (NTP) and TCP ports higher than 1023.

My situation is much better now, while still not completely closing P2 traffic.

This thread is somewhat old but gold.
On theory,wouldnt it any better if we throthle or drop connection exceed certain threshold?
Afterall,nobody but the most determined user would download torrent with low seed/peer per downloaded file?

You can throttle download traffic, but you cant separate download from a web site and download from a p2p site, so you would throttle all download.
When p2p traffic is encrypted, it blends inn to normal traffic.