problem about QoS and firewall (not work)

Home Page Forums Network Management ZeroShell problem about QoS and firewall (not work)

This topic contains 0 replies, has 0 voices, and was last updated by  launcelot 11 years, 7 months ago.

Viewing 2 posts - 1 through 2 (of 2 total)
  • Author
    Posts
  • #40889

    launcelot
    Member

    I’m testing ZeroShell release 1.0beta8 in my testing network with function of QoS and bridge.

    I’m found problem about QoS and firewall, I can’t limit maximum bandwidth of P2P connection and can’t block it.

    1. QoS

    In the test pc that run bittorrent, data transfer are not limit. I checking with “View” and saw it traffic match with DEFAULT class.

    I test configured max bandwidth of DEFAULT class limit to 200Kbps, and next my bittorrent decrease download to 22kBps (176kbps)

    !P2P class not work!

    2. Firewall

    Because I can’t limit in with QoS, I try to testing block bittorrent with firewall.

    I make new firewall to DROP and/or REJECT the bittorrent with L7protocol in all chain (FORWARD, INPUT, OUTPUT)

    But my bittorrent has life, it can download file not match with DROP rule

    !Firewall not work!

    http://upload.siamha.com/v.php?id=75306untitled.JPG

    http://upload.siamha.com/v.php?id=87883untitled1.JPG

    http://upload.siamha.com/v.php?id=73288untitled2.JPG

    http://upload.siamha.com/v.php?id=81861untitled3.JPG

    #46130

    Hi launcelot!

    It’s not possible to create 100% reliable P2P filter. For instance, torrent protocol is able to use end-to-end ecnryption and then even deep packet inspection doesn’t do the trick. I guess other protocols do the same as well or are tending to.

    By the way, L7 filter is not intended to use by firewalls but for QoS shapers. IPP2P filter works only for unencrypted traffic.

    What you can do is to create LOW_PRIORITY traffic class where you put packets you don’t know. All other traffic like VoIP, HTTP, SMTP, IMAP, POP3, DNS can be distinguished by L7-filter or by protocol type (ICMP).

    Cheers
    Jojo

Viewing 2 posts - 1 through 2 (of 2 total)

You must be logged in to reply to this topic.