Hey guys! I have done this, and it works pretty great for what I needed, but I have one question. Is there a way to make it redirect to a website instead of just dropping? I want to tell all customers that it is against ToS to use torrents through a web page. Thanks
The only problem I really see with this, is that it blocks things for keywords. Like me making this post, since it has the keywords in it, I have to use a different gateway to post.. Any idea for a way around that?
Maybe I am wrong, but the proposed solution blocks the downloads of the .torrent files (GET) from known torrent repositories. This is of course important but not effective.
But it won’t block the torrent protocol (file sharing) itself. Which is what I’d like to block, as torrent files can be exchanged via email or even through removable media.
Any idea?
I just copied this from somewhere in the forum, I want to integrate it with blocking downloading of .mp3, *.mp4 etc, how will I add this to the l7-layer, is this one correct cus i dont see it catching any traffic
You can adjust the max-limit to anything higher like 128k
3. /queue tree add name=“streaming2” parent=global packet-mark=streaming2 limit-at=0 queue=default
priority=8 max-limit=48k burst-limit=0
burst-threshold=0 burst-time=0s
today there is so many ways of using torrent, because that blocking it is a never ending work
the main reason to block torrent is because use too much bandwidth
i think there is no need to block torrent i think is better to properly identify torrent and p2p traffic to give it a lower priority and control the congestion it generates and guarantee the good performance on the other applications
I agree with chechito. The only "small problem"™ is to correctly identifying the torrent traffic.
Blocking the download of the torrent file itself is useless as torrents can be added manually from other sources.
I think that only Deep Packet Inspection can help.
Any ideas?
in my case i have identified torrent traffic by discard, detecting another protocols and services usually leave me with torrent on the “unclassified” part of the traffic leaving it with low priority
Do you mean “everything else” (everything but HTTP, HTTPS, SSH, SMTPS, IMAP4S POP3S..) is considered torrent?
If so, which protocols are you considering?
If not, please elaborate.
As I cannot really block P2P in general, I am trying to throttle “everything else”.
The problem is that outgoing P2P can also go to TCP:80, TCP:443, TCP:53 and UDP:53 and so on…
In these cases throttling wouldn’t apply. And this is why I am talking about DPI.
people are using 80 and 443 and 53 or another well known ports because of the blocking, because that is better to throttle than blocking
and with throttle im referencing to give the torrent the possibility of using all the spare bandwidth not throttling it to a ridiculous speeds
Is not perfect but it works in many cases and its free
if some one need better detection of P2P is better to go with an expensive fortigate or another UTM and pay the expensive annual license fee
for example
fortigate 80d recommended for 65mbps of wan channel cost ~750US without services, and ~1.740US with 3 year service subscription that is ~330 US per year of subscription
fortigate 200d recommended for 150mbps of wan channel cost ~2.300US without services, and ~5.200US with 3 year service subscription that is ~960 US per year of subscription
fortigate 600d recommended for 1.100mbps of wan channel cost ~8.000US without services, and ~17.840US with 3 year service subscription that is ~3.280 US per year of subscription
fortigate 1500d recommended for 2.300mbps of wan channel cost ~30.000US without services, and ~66.900US with 3 year service subscription that is ~12.300 US per year of subscription
fortigate 3000d recommended for 6.000mbps of wan channel cost ~60.000US without services, and ~133.800US with 3 year service subscription that is ~24.600 US per year of subscription
tcp ack packets, dns, icmp, udp traffic whit characteristics matching most voip and gaming apps, vpns, rdp, http small traffic connections, http big traffic connections, mail connections, other udp tcp small traffic connections.
the remaining traffic are other tcp and udp connections with big traffic, torrent transfer get on this category
I started by dropping all incoming TCP and UDP traffic (all of it) but those services that go to DMZ.
So there’s no traffic going to LAN, which means “low ID” in the P2P lingo.
Then I started throttling (I’d like to drop, actually) all outgoing traffic from LAN with UDP ports other than 53 (DNS) and 123 (NTP) and TCP ports higher than 1023.
My situation is much better now, while still not completely closing P2 traffic.
This thread is somewhat old but gold.
On theory,wouldnt it any better if we throthle or drop connection exceed certain threshold?
Afterall,nobody but the most determined user would download torrent with low seed/peer per downloaded file?
You can throttle download traffic, but you cant separate download from a web site and download from a p2p site, so you would throttle all download.
When p2p traffic is encrypted, it blends inn to normal traffic.