GFI Software

Welcome to the GFI Software community forum! For support please open a ticket from https://support.gfi.com.

Home » GFI User Forums » Kerio Control » Unable to block torrent
Unable to block torrent [message #130080] Tue, 31 May 2016 15:53 Go to next message
f.maianti is currently offline  f.maianti
Messages: 26
Registered: May 2016
Hi all,
we have just installed and cofigured a Kerio Control NG500 in our company network.
We set up some content filter rule to block dangerous/porno/scam sites and all is working well.
We are trying to block p2p torrent traffic but even if we have created a rule to drop peer-to-peer content our test pc is still downloading from bittorrent.
In the filter log i found a lot of entry like these:

1/May/2016 15:49:26] DENY [Rule] 'Kerio Control Web Filter categories' [Connection] 192.168.30.127:56196 -> edge-star-shv-01-cdg2.facebook.com (179.60.192.3):443, HTTPS [Content] Social Networking edge-star-shv-01-cdg2.facebook.com/
[31/May/2016 15:49:26] DENY [Rule] 'Kerio Control Web Filter categories' [Connection] 192.168.30.127:35111 -> edge-star-shv-01-cdg2.facebook.com (179.60.192.3):443, HTTPS [Content] Social Networking graph.facebook.com/
[31/May/2016 15:49:35] DENY [Rule] 'Kerio Control Web Filter categories' [Connection] 192.168.30.124:3758 -> xx-fbcdn-shv-01-cdg2.fbcdn.net (179.60.192.7):443, HTTPS [Content] Social Networking connect.facebook.net/
[31/May/2016 15:49:38] DENY [Rule] 'Kerio Control Web Filter categories' [Connection] 192.168.30.45:49593 -> edge-mqtt-mini-shv-01-cdg2.facebook.com (179.60.192.34):443, HTTPS [Content] Social Networking mqtt-mini.facebook.com/
[31/May/2016 15:49:52] DENY [Rule] 'Kerio Control Web Filter categories' [Connection] 192.168.30.45:39784 -> instagram-p3-shv-01-cdg2.fbcdn.net (179.60.192.52):443, HTTPS [Content] Social Networking graph.instagram.com/
[31/May/2016 15:49:53] DENY [Rule] 'Kerio Control Web Filter categories' [Connection] 192.168.30.9:54791 -> edge-star-shv-01-cdg2.facebook.com (179.60.192.3):443, HTTPS [Content] Social Networking graph.facebook.com/


so the rule is actually finding and blocking some traffic, but the torrent client is still downloading.

Anyone can help me? What am i doing wrong?
Thanks
Re: Unable to block torrent [message #130082 is a reply to message #130080] Tue, 31 May 2016 16:29 Go to previous messageGo to next message
Petr Dobry (Kerio) is currently offline  Petr Dobry (Kerio)
Messages: 405
Registered: November 2003

Kerio Technologies
Did you enable P2P detection in Advanced settings http://kb.kerio.com/1526 ?

Petr Dobry
Product Development Manager | Kerio

[Updated on: Tue, 31 May 2016 16:29]

Report message to a moderator

Re: Unable to block torrent [message #130084 is a reply to message #130082] Tue, 31 May 2016 16:53 Go to previous messageGo to next message
f.maianti is currently offline  f.maianti
Messages: 26
Registered: May 2016

Yes, i followed the page you linked.
There is no "enable p2p detection", just list of port that kerio will monitor
  • Attachment: kerio.png
    (Size: 140.79KB, Downloaded 1091 times)
Re: Unable to block torrent [message #130112 is a reply to message #130084] Wed, 01 June 2016 21:12 Go to previous messageGo to next message
Petr Dobry (Kerio) is currently offline  Petr Dobry (Kerio)
Messages: 405
Registered: November 2003

Kerio Technologies
That's correct. Torrent traffic is detected automatically by using traffic on those ports.
You can check Active Hosts tab to see if the traffic for specified host is detected a P2P.


Petr Dobry
Product Development Manager | Kerio
Re: Unable to block torrent [message #130181 is a reply to message #130112] Mon, 06 June 2016 08:29 Go to previous messageGo to next message
f.maianti is currently offline  f.maianti
Messages: 26
Registered: May 2016
Now it's working, torrent is blocked by kerio.
Seems like the kerio takes some time to analyze and discover the p2p traffic.

Thanks
Re: Unable to block torrent [message #139290 is a reply to message #130181] Mon, 09 April 2018 13:45 Go to previous message
ipsys is currently offline  ipsys
Messages: 38
Registered: March 2018
Location: Burkina Faso
im not sure i completely understand, and please excuse me for my ignorance. i have followed the kb, but kerio still reports a lot of P2P traffic?

with regards to the KB, do we only need 'content filtering' enabled? or must 'application awareness' also be enabled for the torrentz to be blocked? currently both are enabled, and we see very high cpu (+50%) and memory consumption (75%). with application awareness disabled, cpu use falls by 50% (to roughly 20%) and memory falls by 25% (to 50%).

https://preview.ibb.co/eFzvmc/Screen_Shot_2018_04_09_at_11_36_02_am.png

does this mean that the user is actually downloading the P2P (470mb is not small compared to the rest of the traffic)? its as if the traffic is detected, however not blocked, yet some P2P is detected and blocked?
Previous Topic: kerio box 1120 ver 8.1.X upgrade to 9.X
Next Topic: Intrusion Prevention down again?
Goto Forum:
  


Current Time: Tue Sep 26 05:31:24 CEST 2023

Total time taken to generate the page: 0.06219 seconds