I see the counter for the rule going up. My question is there are still many established tcp connections that are marked as edonkey/bittorrent. Why is the f/w not dropping these connections?
I have rebooted the router to flush all connections after I made the rule. I have watched it for a few days after that but the connections seem to keep coming in.
EVERY time i try to enable all p2p, and rate limit it using simple queue’s, it drops all queue, even the simple queue, it allows the client to have unlimited download/upload access, I have asked around without reply.. How do you enable p2p without loosing your simple queue, and it somehow enabeling unlimited data up/down. anybody else have this problem? I Do… Thanks -Jordan
After I created the rule I rebooted to drop all connections. The firewall rule was in place at the time of the router coming back up. Should all subsequent p2p connections be dropped?
all subsequent connections should be dropped, yes.
However existing connections in my experience are not always dropped. AS far as I can tell this is due to the connection tracking not expiring sessions for the default time which is quite long.
You may have more luck by switching off conntrack rebooting then putting conntrack back on.
I am confused however, are you saying that the firewall rule is not dropping NEW connections as expected or are you trying to deal with existing connections?
Alex;
I am trying to deal with new connections. The drop rule is not dropping new connections. They get established. Maybe something wrong with my router.