Results 1 to 5 of 5
  1. #1
    Untangler
    Join Date
    Dec 2009
    Posts
    38

    Default How to block port hopping apps?

    like torrents

  2. #2
    Untangle Ninja jcoehoorn's Avatar
    Join Date
    Mar 2010
    Location
    York, NE
    Posts
    1,935

    Default

    The trick with these apps is that you never know if you really got them, if they finally ended running on port 80, or if they found somewhere else to hide. And from experience I can tell you that all the attempts and hops can cause inadvertent denial of service problems on your untangle server.

    What I finally settled on to keep up with things is to handle it in three parts:

    1. Use attack blocker to find out who my offenders are
    2. Use QoS to slow traffic from the offenders. This is currently less than satisfying, as they still get a lot of throughput, but I understand that the upcoming version 8 will allow me to slow their traffic to a trickle. In other words: try to torrent, get sent back to 1998 internet speeds.
    3. Additionally quarantine the worst offenders to only allow about 5 ports total, in or out.

    In effect, you prevent the app from hopping ports by allowing the first connection to succeed - a honeypot, if you will, but then you only pass that traffic through at a trickle, such that it becomes a block in everything but name only. I mean, if you want to spend 10 minutes to download one mp3, be my guest.
    Five time Microsoft ASP.Net MVP managing a Lenovo RD330 / E5-2420 / 16GB with Untangle 16.5 to protect a 1Gbps fiber link for ~450 residential college students and associated staff and faculty

  3. #3
    Untangler
    Join Date
    Dec 2009
    Posts
    38

    Default

    How long tell 8.0?

  4. #4
    Untangle Ninja
    WebFooL's Avatar
    Join Date
    Jan 2009
    Location
    Sweden (Eskilstuna)
    Posts
    5,042

    Default

    Quote Originally Posted by Specialsit View Post
    How long tell 8.0?
    There is no public RLS date for 8.0.
    So your guess is as good as mine

  5. #5
    Untangler
    Join Date
    Dec 2009
    Posts
    38

    Default

    hi [QUOTE=mrunkel;116775]It's under development right now, I think it's supposed to go to QA in 4 weeks, figure at least two weeks in QA and then we'll have an Alpha, then Beta, RC, and final. It's about a week between each release once it gets to Alpha, but it could loop in Beta and RC status for a few weeks.

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2