Re: P2P blocking

From: Danial Thom (danial_thom_at_yahoo.com)
Date: 11/28/05

  • Next message: Ion-Mihai Tetcu: "Re: DSPAM and Sendmail"
    Date: Mon, 28 Nov 2005 07:57:57 -0800 (PST)
    To: KrzychK2 <krzychk2@o2.pl>, freebsd-isp@freebsd.org
    
    

    --- KrzychK2 <krzychk2@o2.pl> wrote:

    > Hello freebsd-isp!
    >
    > I'd like to ask, is there any packet using
    > kernel module for rejecting
    > p2p traffic by packet matching??
    >
    > Snort isn't an option for me, because it very
    > overloads system at high
    > traffic and it's very slow.
    >
    > I'm thinking about something for netgraph
    > subsystem.

    There are commercial add-ons for FreeBSD 4.x
    (ET/BWMGR (www.etinc.com) comes to mind), but
    what you want to do is best done with a dedicated
    device. Its very CPU-intensive, as every TCP
    header has to be checked and connections need to
    be tracked. Its not as simple as looking for a
    pattern in a packet, because once a transfer has
    initiated the packets don't have any signatures
    that can be identified.

    Danial

                    
    __________________________________
    Yahoo! Music Unlimited
    Access over 1 million songs. Try it free.
    http://music.yahoo.com/unlimited/
    _______________________________________________
    freebsd-isp@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-isp
    To unsubscribe, send any mail to "freebsd-isp-unsubscribe@freebsd.org"


  • Next message: Ion-Mihai Tetcu: "Re: DSPAM and Sendmail"

    Relevant Pages

    • Re: Snort + (OpenBSD or Linux)
      ... Snort + (OpenBSD or Linux) ... on packet analysis. ...
      (Focus-IDS)
    • [NEWS] Snort TCP Stream Reassembly Integer Overflow Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Snort is a very popular open source network intrusion detection system. ... A workaround for this bug is to disable the TCP stream reassembly module. ... packets with the free command line packet creating utility called hping ...
      (Securiteam)
    • [UNIX] Buffer Overflow in Snort RPC Preprocessor
      ... A buffer overflow has been found in the Snort RPC normalization routines ... The first option will alert on any RPC fragmented record it finds. ... current packet length. ...
      (Securiteam)
    • Re: Linux packet drops
      ... Any older libpcap versions have problems on linux and also results in packet loss. ... We are using Snort on Linux in the binary packet capture mode (capture ... 512MB RAM and 72 GB SATA HDD, ... We also found that the drop increases when the I/O is high, ...
      (RedHat)
    • CORE-2003-0307: Snort TCP Stream Reassembly Integer Overflow Vulnerability]
      ... Snort TCP Stream Reassembly Integer Overflow Vulnerability ... packets with the free command line packet creating utility called hping ...
      (Focus-IDS)