Re: Firewall for blocking P2P programs like fasttrack, morpheus, Gnutella and so on

From: J Jay (jayjay_at_nevertell.net)
Date: 11/13/03


Date: Wed, 12 Nov 2003 23:17:43 GMT

In article <b5dsb.27876$jf4.1593983@news000.worldonline.dk>,
elkvixen@codename42.dk says...
> Hey,
> We at a dormitory are having troubles with some people sharing files using
> P2P programs.
> First of all it gives us unwarranted attention from our ISP, who has told us
> a few times about it.
> Secondly is makes our connection very slow.
> We are 300 people, so just asking them to behave isn't going to solve
> anything.
>
> What we need is a firewall which at least can tell us that a specific MAC
> address or IP address is using a P2P program. This includes using it for
> legal purposes as we can't check what they use it for.
> The best would be a system which logs and blocks. This way we are sure that
> nobody is getting through with their sharing, but also we will know that
> they have done it and we can therefore disconnect them from the Internet
> connection.
>
> I've seen two possiblities for doing the later.
> There is an add on to Iptables called ftwall/p2pwall which blocks fasttrack
> traffic(Since this is the toughest one to block this is especially one we
> want to get rid of). However this gives us the following problems:
> 1) We are having troubles installing it, since the ekspertise in the group
> is not the best. Also the ekspertise in the IT group may drop, since only
> people who live in the dorm may be in the IT group.
> 2) This is a free job, so many hours a week is not an option.
>
> The second is Smoothwall 3 with the addon smoothrule. They seem to say that
> it blocks P2P, but how are they doing it (Just blocking ports or doing
> packet filtering). What if fx. the fasttrack network changes its signature,
> will there be free/cheap upgrades.
>
> I would like to hear anything any of you guys can tell me about these two
> programs, but also more programs which are able to block p2p will be
> appreciated.
>
>
Take a look at:
http://www.sygate.com/solutions/p2p_mp3_compliance.htm
Quote
The Solution
Sygate Secure Enterprise enforces P2P-related security policies on all
computers before they are allowed to connect to the enterprise network.
A fully-integrated security management solution, Sygate enables
companies to:

• Eliminate exposure from the unmanaged use of P2P applications
• Reduce liability resulting from storage of P2P content in violation
of copyright regulations
• Increase employee productivity by eliminating unauthorized P2P use

Sygate Secure Enterprise gives organizations the ability to:

• Find any P2P application running on your network
• Rapidly eliminate all unauthorized use of P2P applications
• Control the conditions under which files may be shared
• Adapt file-sharing policies to individual users, the network
environment, and access method
• Consistently enforce P2P security policies everywhere on the network
end quote
JJ



Relevant Pages

  • RE: IP address conflicts
    ... >> The problem is that if the attacker has a modicum of intelligence they ... > This is a good infrastructure to the network change and it would also ... He is having money troubles. ...
    (freebsd-questions)
  • RE: A question for the list...
    ... >> evolution of the network ... implement and enforce WLAN security policies ... >> enterprise WLANs. ... implement and enforce WLAN security policies to ...
    (Incidents)
  • RE: A question for the list...
    ... attempts to remove the virus from the host. ... -If a command can be given in a channel to "shut down" the network of hosts, ... wireless LANs require network security policies ... that are enforced to protect WLANs from known vulnerabilities and threats. ...
    (Incidents)
  • Re: A question for the list...
    ... Is the attacks a virus really? ... > evolution of the network ... implement and enforce WLAN security policies to lockdown enterprise WLANs. ...
    (Incidents)
  • Re: A question for the list...
    ... can already redirect known attacks and scans to /dev/null. ... > evolution of the network ... wireless LANs require network security policies ... > that are enforced to protect WLANs from known vulnerabilities and threats. ...
    (Incidents)

Quantcast