Community discussions

MikroTik App
 
rastod
Member Candidate
Member Candidate
Topic Author
Posts: 122
Joined: Sat Jun 04, 2005 11:35 pm
Location: Slovakia

P2P detecion

Mon Jan 02, 2006 5:10 pm

Hello,

I think that very high part of P2P is using http protocol and is not detected by mikrotik.
Is it possible?
Will mikrotik prepare some actualization of detection enginee?
 
telephone29
just joined
Posts: 24
Joined: Wed Oct 12, 2005 8:57 pm

Wed Jan 04, 2006 7:25 am

what is not detected? which p2p uses http protocol?
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26922
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia
Contact:

Wed Jan 04, 2006 9:44 am

as far as we know, all most popular p2p programs are detectable by mikrotik routeros. if you have specific programs that are not detectable, let us know which
 
User avatar
hecklertm
Member Candidate
Member Candidate
Posts: 165
Joined: Fri Jun 24, 2005 5:12 am
Location: US

Wed Jan 04, 2006 9:51 am

I know that Kazaa Klite can communicate over port 80, but I probaly tries its default ports first, which you could then identify who is using it through the log of a firewall filter.
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26922
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia
Contact:

Wed Jan 04, 2006 10:03 am

it doesn't matter what ports the p2p softwares use, we detect in more clever ways, by analysing the packet content
 
User avatar
hecklertm
Member Candidate
Member Candidate
Posts: 165
Joined: Fri Jun 24, 2005 5:12 am
Location: US

Wed Jan 04, 2006 10:07 am

Well, it is reasons like that which has us all using MT :D
 
cyb.0rg
newbie
Posts: 39
Joined: Thu Sep 15, 2005 2:52 pm

Thu Jan 05, 2006 2:06 am

Dear normis, i know (100% and it was checked many times) that firewall don't stop p2p bit-torrent traffic
No mistakes! I used different rules, of course drop all-p2p in forward rule, mangle bit-torrent and drop it in rules etc , and after rebooting the same picture -firewall don't stop bit ttorent traffic....

ver 2.9.6
any ideas ?
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26922
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia
Contact:

Thu Jan 05, 2006 8:55 am

we also checked and bit torrent IS BEING detected. show us your rules and how did you determine that it is NOT blocked? be sure that already established connections will not be dropped, only new ones.
 
User avatar
hecklertm
Member Candidate
Member Candidate
Posts: 165
Joined: Fri Jun 24, 2005 5:12 am
Location: US

Thu Jan 05, 2006 9:01 am

I checked and it works on for me using 2.9.10.
 
miroxy
just joined
Posts: 22
Joined: Tue Mar 22, 2005 12:02 am
Location: Serbia
Contact:

Fri Jan 13, 2006 1:40 am

Its working in 2.9.6 too, I suggest cyb.0rg to recheck firewall rules
 
User avatar
djape
Member
Member
Posts: 465
Joined: Sat Nov 06, 2004 7:54 pm
Location: Serbia

Fri Jan 13, 2006 2:55 pm

Bit torrent adn all major p2p softwares are being blocked, but Ares and some unknown (I'll call the customer to ask what is he using) is not being droped.

Cheers all...
 
User avatar
HarvSki
Member
Member
Posts: 395
Joined: Fri May 28, 2004 3:37 pm
Location: London, UK

Fri Jan 13, 2006 3:41 pm

I've seen BIT TORRENT using port 443, I'm not sure if it is implemeting SSL though if it is then surely MT cannot detect it?
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26922
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia
Contact:

Fri Jan 13, 2006 3:49 pm

it does NOT matter what ports any P2P software uses. we detect it more advanced, by traffic and packet structure. I am almost certain that they do not use any kind of encryption on their traffic, so don't worry
 
User avatar
HarvSki
Member
Member
Posts: 395
Joined: Fri May 28, 2004 3:37 pm
Location: London, UK

Fri Jan 13, 2006 3:54 pm

That is reassuring, I know it doesn't matter which port I've seen the p2p try all sorts and the MT just marks it, hahahahahaha :twisted:
 
yancho
Member Candidate
Member Candidate
Posts: 207
Joined: Tue Jun 01, 2004 3:04 pm
Location: LV

Fri Jan 13, 2006 5:16 pm

Maybe we should start worry:
Core Improved: add protocol header encrypt option
 
User avatar
YazzY
Member Candidate
Member Candidate
Posts: 140
Joined: Fri May 28, 2004 3:26 pm
Location: Norway, Østfold
Contact:

Fri Jan 13, 2006 6:34 pm

Just as a side note, you'd lose me as customer the moment you tyrannize me saying what I can and cannot use.
Have a nice weekend :)
 
Diganet
Member
Member
Posts: 342
Joined: Sun Oct 30, 2005 9:30 pm
Location: Denmark
Contact:

Sun Jan 15, 2006 11:10 pm

it does NOT matter what ports any P2P software uses. we detect it more advanced, by traffic and packet structure. I am almost certain that they do not use any kind of encryption on their traffic, so don't worry

Normis, it really could be nice if we could implement our own patterns in the same way as you guys detect P2P.. Protocols like SIP are very needed where i am and i could do a lot more in the market if i was able to queue that kind of traffic.

Regards

Henrik
 
skordan
just joined
Posts: 22
Joined: Wed Feb 02, 2005 1:13 am
Location: Poland
Contact:

p2p detection

Fri Jan 20, 2006 1:11 pm

I see the same the bit komet is working all day (i have p2p blocked from 6am to 11 pm) mayby is the problem with "...already established connections will not be dropped, only new ones." but what can we doing in such situation ? limiting connections per user ?
 
User avatar
Hugh Hartman
Frequent Visitor
Frequent Visitor
Posts: 92
Joined: Fri May 28, 2004 2:01 pm
Location: Fort Kent, Maine

Sat Jan 21, 2006 1:33 pm

Yes- I limit the connection time and the number of connections..
 
User avatar
djape
Member
Member
Posts: 465
Joined: Sat Nov 06, 2004 7:54 pm
Location: Serbia

Sun Jan 22, 2006 1:26 pm

@skordan

Do script that will reboot router 6 am and after that all p2p will be droped. Nobody will complain for 30 sec pause in the morning :)

Cheers...

Who is online

Users browsing this forum: bonamin, mkx, pmh, pmichel, sindy, vnl and 79 guests