?
Solved

Block P2P on a Cisco router

Posted on 2010-08-20
3
Medium Priority
?
1,300 Views
Last Modified: 2012-05-10
Greetings,

I've put ip nbar protocol-discovery on the FastEthernet interfaces of my Cisco 2800 (ver 12.4(4)). I created a class-map to match the protocols of some known p2p apps, created a policy-map to drop the matched traffic and added the service policy to the interface. The problem is, when I run "show ip nbar protocol-discovery" eDonkey is not being blocked. Below is the relavent config:

class-map match-any p2p
 match protocol edonkey
 match protocol fasttrack
 match protocol gnutella
 match protocol kazaa2
 match protocol winmx
 match protocol novadigm

 policy-map block-p2p
 class p2p
   drop

interface FastEthernet0/0
 no ip address
 ip access-group 150 in
 no ip redirects
 no ip unreachables
 ip nbar protocol-discovery
 ip flow ingress
 ip flow egress
 duplex auto
 speed auto
 no cdp enable
 service-policy input block-p2p
 service-policy output Voice

!
interface FastEthernet0/0.11
 description Local LAN
 encapsulation dot1Q 11
 ip address 10.1.X.1 255.255.255.0
 no ip redirects
 no ip unreachables
 no ip proxy-arp
 ip nbar protocol-discovery
 ip flow ingress
 ip flow egress
 no cdp enable
 service-policy input block-p2p
!
interface FastEthernet0/0.200
 description Local WAN
 encapsulation dot1Q 200
 ip address 10.1.YYY.5 255.255.255.0
 no ip redirects
 no ip unreachables
 no ip proxy-arp
 ip nbar protocol-discovery
 ip flow ingress
 ip flow egress
 ip ospf priority 0
 service-policy input block-p2p
 
Results of show policy-map int fa0/0.11
 FastEthernet0/0.11

  Service-policy input: block-p2p

    Class-map: p2p (match-any)
      6155 packets, 395222 bytes
      5 minute offered rate 0 bps, drop rate 0 bps
      Match: protocol edonkey
        0 packets, 0 bytes
        5 minute rate 0 bps
      Match: protocol fasttrack
        0 packets, 0 bytes
        5 minute rate 0 bps
      Match: protocol gnutella
        0 packets, 0 bytes
        5 minute rate 0 bps
      Match: protocol kazaa2
        0 packets, 0 bytes
        5 minute rate 0 bps
      Match: protocol winmx
        6128 packets, 392940 bytes
        5 minute rate 0 bps
      Match: protocol novadigm
        27 packets, 2282 bytes
        5 minute rate 0 bps
      drop

Results of show ip nbar pro int fa0/0.11

 FastEthernet0/0.11
                            Input                    Output
                            -----                    ------
   Protocol            acket Count             Packet Count
                            Byte Count               Byte Count
                            5min Bit Rate (bps)      5min Bit Rate (bps)
                            5min Max Bit Rate (bps)  5min Max Bit Rate (bps)
   ------------------------ ------------------------ ------------------------
   edonkey            1842915                  1859275
                            1475234220               1874109161
                            0                        0
                            9654000                  14592000
   http                   1096487                  2265466
                            276457930              1728864847
                            33000                      81000
                            218000                    8664000

What am I missing?

Thanks
Paul
0
Comment
Question by:SBSIAdmin
  • 2
3 Comments
 
LVL 4

Accepted Solution

by:
Tory W earned 2000 total points
ID: 33488844
Looks like you may need the new edonkey pdlm. Cisco has the instructions here.  Other than that your config looks good.  

I think the older versions of limewire were covered by how you are doing it but the newer versions need the new pdlm.

Hope this helps.

0
 

Author Comment

by:SBSIAdmin
ID: 33617731
Sorry for the delay, I've been on vacation. I'll download the new pdlms and give it a shot.
0
 

Author Comment

by:SBSIAdmin
ID: 33627181
Thanks, that resolved the issue.
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, the configuration steps in Zabbix to monitor devices via SNMP will be discussed with some real examples on Cisco Router/Switch, Catalyst Switch, NAS Synology device.
LinkedIn blogging is great for networking, building up an audience, and expanding your influence as well. However, if you want to achieve these results, you need to work really hard to make your post worth liking and sharing. Here are 4 tips that ca…
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…

850 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question