227
Chapter 17
Advanced security features
17.1 P2P Eliminator
Peer-to-Peer
(
P2P
) networks are world-wide distributed systems, where each node can repre-
sent both a client and a server. These networks are used for sharing of big volumes of data
(this sharing is mostly illegal).
DirectConnect
and
Kazaa
are the most popular ones.
In addition to illegal data distribution, utilization of
P2P
networks overload lines via which
users are connected to the Internet. Such users may limit connections of other users in the
same network and may increase costs for the line (for example when volume of transmitted
data is limited for the line).
WinRoute
provides the
P2P Eliminator
module which detects connections to
P2P
networks and
applies specific restrictions. Since there is a large variety of
P2P
networks and parameters at
individual nodes (servers, number of connections, etc.) can be changed, it is hardly possible
to detect all
P2P
. However, using various methods (such as known ports, estab-
lished connections, etc.), the
P2P Eliminator
is able to detect whether a user connects to one
or multiple
P2P
networks.
The following restrictions can be applied to users of
P2P
networks (i.e. to hosts on which
clients of such networks are run):
•
Blocking options
— it is possible to block access to the Internet for a particular host or
to restrict the access only to selected services (e.g. web and e-mail),
•
Bandwidth limitation
— it is possible to decrease speed of data transmission of
P2P
clients so that other users are not affected by too much data transferred by the line.
P2P Eliminator Configuration
P2P
networks are detected automatically (the
P2P Eliminator
module keeps running). To set
the
P2P Eliminator
module’s parameters, go to the
P2P Eliminator
tab in the
Configuration
→
Advanced Options
section.
As implied by the previous description, it is not possible to block connections to particular
P2P
networks.
P2P Eliminator
allows complete blocking of all traffic (i.e. access to the Internet
from the particular host), enabling of only such services which are securely not associated
with P2P networks or limiting of bandwidth (transfer speed) that can be used by
P2P
networks
clients. The settings will be applied to all clients of
P2P
networks detected by
P2P Eliminator
.
According to thorough tests, the detection is highly reliable (probability of failure is very low).
Summary of Contents for Firewall6
Page 1: ...Kerio WinRoute Firewall 6 Administrator s Guide Kerio Technologies...
Page 129: ...8 5 HTTP cache 129...
Page 404: ...404...