Solved

blocking p2p traffic on Cisco 1800 router.

Posted on 2010-09-23
5
1,652 Views
Last Modified: 2012-05-10
Hi Experts,

Is it possible to block p2p traffic on routers? i know we can do it using NBAR config but it did not help. i was still able to download stuff using vuze. Please help...
0
Comment
Question by:ullas_unni
  • 2
  • 2
5 Comments
 
LVL 24

Accepted Solution

by:
rfc1180 earned 500 total points
ID: 33746673
0
 
LVL 2

Expert Comment

by:fs40490
ID: 33746721
the issue is that many p2p applications use standard ports that are allowed.  Because a router uses L3/4 controls to permit/prevent traffic the router has no way to determine what type of traffic is passing on those ports and protocols.  You need to have something that inspects at a higher level on the ISO model.  Application layer firewalls can definitely block this type of traffic, and also those devices that do deep packet inspection work.  

The basic issue is that the programs generally use standard ports and protocols, so you need something that can inspect what type of traffic is traversing the ports, which routers do not generally do.
0
 
LVL 24

Expert Comment

by:rfc1180
ID: 33746769
looks like you have a PIX (Sorry missed that):

So this might help:

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00801e419a.shtml

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808c38a6.shtml

As already stated; to be really useful, stateful/deep packet inspection is what you really need. There have been successful attempts in blocking P2P.

Billy
0
 
LVL 4

Author Comment

by:ullas_unni
ID: 33747273
well not a PIX..  its on routers... i was looking at the first doc.. seems like it should help.. let me try it and let you know...
0
 
LVL 4

Author Comment

by:ullas_unni
ID: 33788991
thanx.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
HSRP needed? 4 31
EIGRP Full Mesh 2 36
EIGRP Configuration 2 18
How do to revert to start-up config on a Cisco Switch Stack 11 19
From Cisco ASA version 8.3, the Network Address Translation (NAT) configuration has been completely redesigned and it may be helpful to have the syntax configuration for both at a glance. You may as well want to read official Cisco published AS…
Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now