Monday, June 1, 2020

Best gear / Router or OS to block Torrents DPI style

Hi.

I've been using an Edgerouter Lite to do DPI based torrent blocking for our guest network. We purchased an RB4011 (MikroTik) and none of the layer7 based P2P blocking works since most clients are encrypted, and the P2P option was removed the newer versions of Router OS.

We run a public guest network which was frequently receiving DMCA notices (go figure, free 100mbps internet in a zone with dsl and dialup). We use QOS and what not, so the ER-L doesn't have enough OOMF for this, we considered an ER-4 but that just seemed a little low end too, so we ultimately went for the RB4011. I'd like to use the ER-L elsewhere now, and was wondering if you guys had any solutions to this. We're open to using OPNSense, VyOS, PfSense, etc. We're currently at a loss though since google-fu does not bring up anything.

We know some clients use

Bittorrent

uTorrent

qBittorrent

and usual sites like tpb, kat, etc. Right now we've set it to detect users torrenting and close all dst 1025-65535 for 24 hours. That's not the best solution though since it breaks discord, whatsapp and more. (Yeah I understand they're breaking a rule, but I feel like we should be able to handle this another way.)

has anyone found a solution to this?



No comments:

Post a Comment