Solved

blocking p2p traffic on Cisco 1800 router.

Posted on 2010-09-23
5
1,661 Views
Last Modified: 2012-05-10
Hi Experts,

Is it possible to block p2p traffic on routers? i know we can do it using NBAR config but it did not help. i was still able to download stuff using vuze. Please help...
0
Comment
Question by:ullas_unni
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 24

Accepted Solution

by:
rfc1180 earned 500 total points
ID: 33746673
0
 
LVL 2

Expert Comment

by:fs40490
ID: 33746721
the issue is that many p2p applications use standard ports that are allowed.  Because a router uses L3/4 controls to permit/prevent traffic the router has no way to determine what type of traffic is passing on those ports and protocols.  You need to have something that inspects at a higher level on the ISO model.  Application layer firewalls can definitely block this type of traffic, and also those devices that do deep packet inspection work.  

The basic issue is that the programs generally use standard ports and protocols, so you need something that can inspect what type of traffic is traversing the ports, which routers do not generally do.
0
 
LVL 24

Expert Comment

by:rfc1180
ID: 33746769
looks like you have a PIX (Sorry missed that):

So this might help:

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00801e419a.shtml

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808c38a6.shtml

As already stated; to be really useful, stateful/deep packet inspection is what you really need. There have been successful attempts in blocking P2P.

Billy
0
 
LVL 4

Author Comment

by:ullas_unni
ID: 33747273
well not a PIX..  its on routers... i was looking at the first doc.. seems like it should help.. let me try it and let you know...
0
 
LVL 4

Author Comment

by:ullas_unni
ID: 33788991
thanx.
0

Featured Post

Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
On Feb. 28, Amazon’s Simple Storage Service (S3) went down after an employee issued the wrong command during a debugging exercise. Among those affected were big names like Netflix, Spotify and Expedia.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

691 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question