Skype Traffic - Firewall ; SuperNodes

Mikrotik device configured with multiple subnets / pools with firewall rules to tighten security between users.

Would like Skype traffic between (local) users to remain local ; at this stage an international supernode is used to route traffic.

Possible to keep traffic local with either firewall rule / local proxy?

Any help / advice will be appreciated.

Not mut knowledge about Skype here, but p2p connections should be direct (no in-the-middle node that traffic goes “through”).

Can your clients establish a tcp connection directly (traffic going only through your routers)? Probably Yes.

Try a tracert command. Post results here.

Regards
dot-bot :wink:

Even if you close everything else at your gateway box,Skype will get through a squid proxy , if you need to stop it in a hurry,transparently proxy at your gateway and put in regex in squid.conf that will drop CONNECTS to decimal ips…this works but will break other stuff too,and is far from ideal