Community discussions

MikroTik App
 
User avatar
kayesar99955
just joined
Topic Author
Posts: 11
Joined: Thu May 31, 2018 12:22 pm

L7

Thu Feb 06, 2020 2:50 pm

One::>>> Hi, attention forum guru !!
I want to block any type of websites from layer 7 , want to block downloading all type AUDIO VIDEO Format LIKE MP3.MP4,MKV.WMKV, etc . so that no one can download any audio video from my Local Network and is there any firewall rules to block this with layer 7.

Two::>>how can i block any .exe or any format of file . from layer 7. what is the best solution so that I can apply any mikrotik router and any industry.

Please I want to have appropriate answer form forum guru!

Thanks
 
Sob
Forum Guru
Forum Guru
Posts: 9188
Joined: Mon Apr 20, 2009 9:11 pm

Re: L7

Thu Feb 06, 2020 6:57 pm

You're not looking for guru, you want magician (the supernatural kind).

Short answer: What you want is impossible.

Long answer: What you want may work in limited way with unencrypted http. But since today almost everything uses encrypted https and L7 can't see what's inside, it's waste of time to bother with http, because everyone will simply download those things over https.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 22509
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: L7

Thu Feb 06, 2020 7:45 pm

Hmmm, if the requirement is to prevent video downloading/streaming, perhaps the solution is to apply to the offending IPs, or subnets or all IPs (and make your own PC an exception) RATE LIMITING.
Think of it not necessarily a total bandwidth allotment but an inability to push/pull more than X Kbps of data such that any one is quickly discouraged from attempting to do so.........it would take hours.

Now Sob, how do we do that on MT???
 
Sob
Forum Guru
Forum Guru
Posts: 9188
Joined: Mon Apr 20, 2009 9:11 pm

Re: L7

Thu Feb 06, 2020 8:03 pm

Rate limiting is not too difficult, look at queues. The problematic part is how to tell router what to limit. If you'd want to limit some IP addresses (be it clients or servers) as whole, it's easy. But if you want to be more specific (e.g. limit only videos, but not other things), you're quickly getting closer to the impossible.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 22509
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: L7

Thu Feb 06, 2020 8:54 pm

Concur, I was strictly thinking either SUBNET, or ADDRESS LIST of obnoxious IP addresses, or blanket entire LAN, and make exception for ones own PC.

(With regard to type, unless the traffic as identified CoS or something, a way to identify it or mangle it.................. no way I can see of picking it out from noise.)