Firewall Against P2P
Posted: Fri Sep 23, 2011 12:04 pm
hi all
i have created a simple firewall to block p2p for an internet cafe. is this practical? wondering what other services are used mostly for me to add to the accept range.
[admin@MikroTik] > ip
[admin@MikroTik] /ip> firewall
[admin@MikroTik] /ip firewall> filter
[admin@MikroTik] /ip firewall filter> print
Flags: X - disabled, I - invalid, D - dynamic
0 ;;; default configuration
chain=input action=accept protocol=icmp
1 ;;; default configuration
chain=input action=accept connection-state=established
in-interface=ether1-gateway
2 ;;; default configuration
chain=input action=accept connection-state=related
in-interface=ether1-gateway
3 ;;; default configuration
chain=input action=drop in-interface=ether1-gateway
4 chain=forward action=accept connection-mark=http
5 chain=forward action=accept connection-mark=DHCP
6 chain=forward action=accept connection-mark=DNS
7 chain=forward action=accept connection-mark=FTP
8 chain=forward action=accept connection-mark=bgp
9 chain=forward action=accept connection-mark=http
10 chain=forward action=accept connection-mark=imap
11 chain=forward action=accept connection-mark=msn
12 chain=forward action=accept connection-mark=pop3
13 chain=forward action=accept connection-mark=smtp
14 chain=forward action=accept connection-mark=ssh
15 chain=forward action=accept connection-mark=ssl
16 chain=forward action=accept connection-mark=yahoo
17 chain=forward action=accept connection-mark=https
18 chain=forward action=drop
regards
i have created a simple firewall to block p2p for an internet cafe. is this practical? wondering what other services are used mostly for me to add to the accept range.
[admin@MikroTik] > ip
[admin@MikroTik] /ip> firewall
[admin@MikroTik] /ip firewall> filter
[admin@MikroTik] /ip firewall filter> print
Flags: X - disabled, I - invalid, D - dynamic
0 ;;; default configuration
chain=input action=accept protocol=icmp
1 ;;; default configuration
chain=input action=accept connection-state=established
in-interface=ether1-gateway
2 ;;; default configuration
chain=input action=accept connection-state=related
in-interface=ether1-gateway
3 ;;; default configuration
chain=input action=drop in-interface=ether1-gateway
4 chain=forward action=accept connection-mark=http
5 chain=forward action=accept connection-mark=DHCP
6 chain=forward action=accept connection-mark=DNS
7 chain=forward action=accept connection-mark=FTP
8 chain=forward action=accept connection-mark=bgp
9 chain=forward action=accept connection-mark=http
10 chain=forward action=accept connection-mark=imap
11 chain=forward action=accept connection-mark=msn
12 chain=forward action=accept connection-mark=pop3
13 chain=forward action=accept connection-mark=smtp
14 chain=forward action=accept connection-mark=ssh
15 chain=forward action=accept connection-mark=ssl
16 chain=forward action=accept connection-mark=yahoo
17 chain=forward action=accept connection-mark=https
18 chain=forward action=drop
regards