PDA

View Full Version : Hey, I'm finally first, for a change


Crusher
05-08-2008, 12:18 PM
I have 5.2 installed and running. I have blocked all p2p protocols but I can still access Limewire. I believe the signature for Limewire is the same as for Gnutella. The event viewer shows a pile of events that are shown as Gnutella events when I use Limewire and shows them as "blocked in block list" but in fact they are being allowed through.
The previous version of Untangle blocked Limewire (Gnutella) quite nicely. What is happening ?????

Silver Bullet
05-08-2008, 12:19 PM
What is happening ?????

Wassssupppp!!

dmorris
05-08-2008, 12:20 PM
Wassssupppp!!

WAAAAAAAAAAAAAAASSSUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUP !!



Did you update your client software? I don't think the signature changed for gnutella.

you can check the old signature here: http://untangledemo.untangle.com (still running 5.0)

Limwire is gnutella as far as I know.

Crusher
05-08-2008, 12:33 PM
Yes, Limewire and Gnutella are the same thing. The Protocol List shows Gnutella, but the signature shows that it includes Limewire. I have that blocked but I can still access Limewire and download files. When I do, the Event viewer shows that Untangle thinks it is blocking Gnutella but in fact it is not. This worked fine in previous versions.

dmorris
05-08-2008, 12:35 PM
Yes, Limewire and Gnutrella are the same thing. The Protocol List shows Gnutella, but the signature shows that it includes Limewire. I have that blocked but I can still access Limewire and download files. When I do, the Event viewer shows that Untangle thinks it is blocking Gnutella but in fact it is not. This worked fine in previous versions.

It may be blocking some of the sessions, however often many of the clients implement alternative methods that don't get blocked.

this will mean it will get detected but not blocked because the alternatives work :(

are the signatures the same as the old version?

Silver Bullet
05-08-2008, 12:36 PM
Also try turning on the "p2p" Gnutella blocking in the Intrusion Prevention module.

Make sure that your connection is not open before trying to test it's effectiveness again.

Crusher
05-08-2008, 12:38 PM
The signatures appear to be the same on both the old and the new versions. Also, there are no events being shown as "not blocked in block list" so it seems to me that the ones being "blocked" are in fact NOT being blocked.

sky-knight
05-08-2008, 12:43 PM
I think there was another post that was trying this same thing that discovered like the current AIM Limewire is capable of bypassing the current rules.

However, I do believe the web filter set to block connections to limewire.com fixed the issue in that case.

Crusher
05-08-2008, 12:52 PM
I tried blocking Limewire.com in the Web Filter as suggested, but I still can download files using Limewire.

Silver Bullet
05-08-2008, 12:54 PM
Unplug the external interface of Untangle and see if you can download anything with Limewire then.:popcorn:

Crusher
05-08-2008, 12:56 PM
If I unplug the external interface how would ANYTHING work????????

Silver Bullet
05-08-2008, 01:02 PM
I'm in just one of those moods... sorry.

Crusher
05-08-2008, 01:13 PM
I'm trying to solve a problem here. I really don't need any smart-a*** responses!:mad: If you don't have anything constructive to add, why not go play games somewhere else?

ronnikat
05-08-2008, 02:23 PM
If I unplug the external interface how would ANYTHING work????????

Actually a lot of folks don't realize that they have the Ext and Int Backwards. Its a common problem (Hey even I do it if I am not paying attention)

Crusher
05-08-2008, 02:33 PM
Actually a lot of folks don't realize that they have the Ext and Int Backwards. Its a common problem (Hey even I do it if I am not paying attention)

And just what would that have to do with solving the problem at hand? If the Protocol Control is reporting that it is blocking dozens of Gnutella requests when I try to use Limewire but they are still coming through, it cannot have anything to do with the connections. (Also, several url's are blocked in the Web Filter and that is working correctly.) SB was just trying to be a smart-a**.

sky-knight
05-08-2008, 02:35 PM
And the Silver Bullet solution strikes again..

Crusher
05-08-2008, 02:37 PM
Hopefully there is someone monitoring this forum that can attempt to provide some legitimate assistance.

sky-knight
05-08-2008, 02:42 PM
Honestly I don't know if there is a direct answer on this question.

That application is really good at navigating around blocks and firewalls. The only thing I can even think of suggesting is shutdown the entire network except one pc. Put a software firewall on said PC and block all applications except limewire from the internet. Get into TCPDump on the UT server with the limewire blocks enabled and see what is passing. From that information you should be able to build a protocol/web/whatever block to stop the traffic from all the insane paths that limewire takes. I might do just that myself just to save myself the future problem, because I have to deal with this application specifically myself. The time to do this however, might be rather extended, my schedule is full!

Crusher
05-08-2008, 02:50 PM
Thanks for the assistance. The surprising thing is that this worked fine on the previous versions of UT. Perhaps Limewire upgraded their ability to sneak past the Protocol Control and similiar filters. Hopefully blocking the rest of the p2p applications will work....I don't have them installed so can't test them.:(

dmorris
05-08-2008, 02:57 PM
Hopefully there is someone monitoring this forum that can attempt to provide some legitimate assistance.

It must be painful having all these experts help you and with a fun attitude no less. :)

I echo sky-knights reply - tcpdump/wireshark is probably your best tool at this point to help you pinpoint how to stop it.

I don't think untangle protocol control has changed - they probably changed the application.

Crusher
05-08-2008, 07:08 PM
It must be painful having all these experts help you and with a fun attitude no less. :)



:confused::confused::confused:

dmorris
05-08-2008, 11:54 PM
:confused::confused:

just joking around with you. hang around a bit more and you'll notice we do that a lot :)

just wait till silver bullet starts drinking! :mdh:

sky-knight
05-09-2008, 09:40 AM
So if Silver does the drinking why does the emote reference mdh?

mdh
05-09-2008, 11:40 AM
Because I try to get Silver Bullet to send me a Franziskaner or Paulaner or Hacker-Pschorr or anything that is German, wheat and good!

sky-knight
05-09-2008, 05:17 PM
So you're trying to have Silver send you a real beer when his name has a direct reference to Rocky Mountain piss water?

Silver Bullet
05-09-2008, 05:17 PM
Rocky Mountain piss water?

EASY NOW! Those are fighting words.:lol

mdh
05-09-2008, 05:26 PM
:mdh: I'll drink to that! :mdh:

Silver Bullet
05-09-2008, 05:32 PM
Well I'm drinking to it too... doesn't mean I have to like what I'm drinking to though.

mdh
05-09-2008, 05:57 PM
Yeah...I used to be married too.