LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 10-16-2006, 12:29 AM   #1
nesargha
Member
 
Registered: May 2006
Distribution: rhel 4, red hat 9, fedora core 2
Posts: 51

Rep: Reputation: 15
how does P2P s/w s work, and how to block to them using squid


hi,

we have red hat 9 server with squid as proxy and winXP clients. I would like to know how P2P s/ws like(kazza, edonkey, morpheus etc..) work and how to block these softwares. The problem we have very low bandwidth internet connection so we cannot afford to have these s/w running in the the client computers, even though i have blocked the sites where these s/ws are available, some users of the network have installed them using CDs.
so i would like to know how can i block these s/w and how they work.

thanks in advance
 
Old 10-16-2006, 05:52 AM   #2
rvw
LQ Newbie
 
Registered: Oct 2005
Posts: 8

Rep: Reputation: 0
Hi

These guys can be fairly hard to block since they use port-hunting techniques to find open ports that they can use. However you can make a good start by setting up a firewall and a good tool to help with this is firehol -- firehol.sourceforge.net has all the details.

I hope that this helps.

Richard.
 
Old 10-16-2006, 08:26 AM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
The problem we have very low bandwidth internet connection so we cannot afford to have these s/w running in the the client computers
This solution mimics that of an authoritarian system of government under absolute control of a single person*:
- Have a network acceptable usage policy (don't check legal issues since you're doin things the Junta way).
- Force network users to adhere (psyops, demotion, blackmail, you name it).
- Be able to enforce it (see prev).
- Restore each users OS partition (force users to do it instead of using a nighttime cronjob).
- Deny all outbound traffic (burn Wifi AP's at the stake and flog all modems to death).
- Force all traffic through a transparent proxy using Snort-inline with the P2P rulesets before hitting Squid.
- Use traffic monitoring to spot anything suspicious.
- Regularly hold festive meetings underscoring the "freedom" your leadership brought, the need to achieve the ten year plan's "Glorious Goals", the need to combat The Enemy continuously and don't forget to end with singing the Farm anthem...

* meaning that your actions will encourage them to actively find ways to circumvent these.
 
Old 10-17-2006, 12:50 AM   #4
nesargha
Member
 
Registered: May 2006
Distribution: rhel 4, red hat 9, fedora core 2
Posts: 51

Original Poster
Rep: Reputation: 15
hi,

Thanks for the reply.

I know its hard to implement but we have no other ways, with a 512 kbps shared internet connection for which a max of 10 users is the recommended we have more than 20 clients. so we have to implement measures like this.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
iptables-p2p - Instalation problems | How to block p2p with iptables Woping Linux - Networking 0 03-14-2006 12:56 PM
Block P2P on Shorewall Firewall bharathvn Linux - Security 6 02-13-2006 02:25 AM
Can you block programs (like p2p) by protocol examining? servnov Linux - Networking 3 10-02-2005 04:33 PM
iptables how to block p2p (missing ipp2p) Neze Linux - Networking 1 02-01-2005 01:33 PM
block p2p tcby Linux - Security 1 10-28-2001 10:54 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 11:24 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration