Community discussions

MikroTik App
 
raktim
Member Candidate
Member Candidate
Topic Author
Posts: 184
Joined: Fri Jun 15, 2007 7:22 am

block outgoing VPN

Fri Jun 13, 2008 2:25 pm

i have a client, who took 2 Mb from my isp. He has made a VPN by using 80 port. How can i block his outgoing VPN??? ANY Idea???
 
User avatar
andrewluck
Forum Veteran
Forum Veteran
Posts: 700
Joined: Fri May 28, 2004 9:05 pm
Location: Norfolk, UK

Re: block outgoing VPN

Fri Jun 13, 2008 2:57 pm

Block port 80 :lol:

Otherwise you might be able to do something using L7 filters.

Kind regards

Andrew
 
User avatar
Chupaka
Forum Guru
Forum Guru
Posts: 8712
Joined: Mon Jun 19, 2006 11:15 pm
Location: Minsk, Belarus
Contact:

Re: block outgoing VPN

Fri Jun 13, 2008 7:51 pm

maybe block GRE protocol? what kind of VPN does he use?
 
raktim
Member Candidate
Member Candidate
Topic Author
Posts: 184
Joined: Fri Jun 15, 2007 7:22 am

Re: block outgoing VPN

Sun Jun 15, 2008 1:49 pm

Below is my torch result..........................
rp_torch.JPG

how can i block this by using layer 7 ??????


thnxs,
raktim
You do not have the required permissions to view the files attached to this post.
 
User avatar
Chupaka
Forum Guru
Forum Guru
Posts: 8712
Joined: Mon Jun 19, 2006 11:15 pm
Location: Minsk, Belarus
Contact:

Re: block outgoing VPN

Sun Jun 15, 2008 3:37 pm

why not just block port 80 for UDP?
 
raktim
Member Candidate
Member Candidate
Topic Author
Posts: 184
Joined: Fri Jun 15, 2007 7:22 am

Re: block outgoing VPN

Mon Jun 16, 2008 5:36 am

i did it, But i m curious about layer7 filter. i upgraded my router to v3.10 just for layer7.

Any idea, how to block this in layer7 filter.


thnxs,
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26954
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia
Contact:

Re: block outgoing VPN

Mon Jun 16, 2008 8:56 am

you need to use packet sniffer to determine if there is any kind of pattern in his connection. for example when he makes the connection, the initial packets could be the same always. so copy those strings and make into a l7 filter. L7 will consume a lot of resources, because it will have to look into every packet :)