Effectively blocking Bit Torrent

I am using BackTrack 5 to help monitor Bit Torrent since I have been completely ineffective in blocking it via my Cisco 5505 Firewall.  I have now seen several outbound TCP connections with the connection being to my firewall's IP address.  I am a rookie when it comes to using Cisco's rather clunky interface and am struggling with this.   I am a software developer with very few networking skills in a company of 5!  Can anyone help with the proper way to block bit torrent downloads on my Cisco asa 5505 or tell me why my BackTrack system is telling me that the firewall is connecting to the pirate bay?
Thanks in advance for any help you can give me!

It would help if you provided a white-washed network diagram to see where the BackTrack software is installed, listening to traffic.  Now if I were a betting person, I would lay good odds that the address  BackTrack sees is the same NAT IP used for traffic to go to Internet and  BackTrack is listening to traffic after it exits the ASA.
One of the things I have to be beneficial on many levels is implementing a software which uses netflow to track traffic, Scrutinizer for instance.  You have all interfaces on the ASA monitored and create filters to look into almost anything crossing the ASA.  (Not to plug Scrutinizer, just found it to be the best.)
Another benefit is to use it to see what applications, users, etc are eating traffic.  I found a company which released new code to their web servers that did not compress pdf's after being generated, part of new code.  As a result we saw a significant portion of the network traffic increase, almost double, and would not have found the culprit had it not been for netflow.

Similar Messages

  • Blocking Bit-Torrent and other P2P softwares

    Hello Dear All
    I need to block All P2P Activity (ASA 5525) from VPN Users (outside), I tried some access lists, but they didn't take any action.
    could you please assist me the access lists/policy-maps that you have done before and its working.
    As you see output of service-policy there are matching but there is no any packet dropped.
    Output :
    ASA# sh service-policy global inspect http
    Global policy:
      Service-policy: global_policy
        Class-map: inspection_default
          Inspect: http Drop-P2P, packet 942279, lock fail 0, drop 0, reset-drop 0, v6-fail-close 0
            protocol violations
              log, packet 123
            match request header user-agent regex _default_gator
              drop-connection log, packet 0
            match response header regex _default_x-kazaa-network count gt 0
              drop-connection log, packet 0
            class bit-torrent-tracker
              drop-connection log, packet 0
    ASA# sh service-policy global inspect http
    Global policy:
      Service-policy: global_policy
        Class-map: inspection_default
          Inspect: http Drop-P2P, packet 980730, lock fail 0, drop 0, reset-drop 0, v6-fail-close 0
            protocol violations
              log, packet 131
            match request header user-agent regex _default_gator
              drop-connection log, packet 0
            match response header regex _default_x-kazaa-network count gt 0
              drop-connection log, packet 0
            class bit-torrent-tracker
              drop-connection log, packet 0
    Thank You

    Hi Ali,
    Your VPN users connects through internet and get internet access from the ASA connected internet link??? There you want to block the bit torrent and P2P?? Please describe your setup....
    Also provide your configurations that is related to P2P & Bit Torrent blocking
    Remember one thing.
    The ASA can block P2P type applications only if P2P traffic is being tunneled through HTTP. Also, ASA can drop P2P traffic if it is tunneled through HTTP. If that is already been proxied then its not poosible for asa to block such traffic.
    http://www.giac.org/paper/gsec/3123/peer-to-peer-p2p-file-sharing-applications-threat-corporate-environment/103882
    Regards
    Karthik

  • Blocking Bit Torrent

    Hi all,
    This isnt really a broadband problem, the issue is with my housemate. he is downloading torrents on my 3mb connection which i pay for which is taking all the bandwidth.
    I have told him to stop but he persists, rather than kicking him off the internet i would like to either throttle his connection to the Homehub or block bittorrent altogether.
    Does anyone know if BT have the capabilities to block torrent files?
    I have completed the CCNA so i am aware of port forwarding traffic to a non existant address such as 0.0.0.0 on 255.255.255.0 and have forwarded ports 6969 up to 8000 on the homehub to my laptop but its made no difference.
    I'm getting a Virgin connection soon for myself but i would like to sort this out before then so even if i have that connection and he has the BT one he cant use bittorrent. Yes its harsh but its got on my nerves enough now.
    any help will be greatly appreciated.
    Tom

    i dont think ive got to that point yet though i am very close.
    I'm thinking of getting the 50Mb virgin connection and simply not telling him or maybe showing it off to him.  Just had a plan of instead of blocking common ports bittorrent uses i will do a clean sweep and only let him access port 80 so all he can do his access websites. No more xbox live, spotify, bittorrent, PC gaming  etc for him.
    He should have really thought about stopping using bittorrent when i told him to, little does he know i have studied networking for over 4 years.
    Question remains open "can BT block bittorrent on their end?"

  • Restrict P2P (Bit Torrent / Limewire) On Airport Extreme

    Hey all,
    I am just wondering if it's possible to only allow one computer to access Bit Torrent or Limewire connections and leaving out my son for accessing the same things?. I have an Apple Airport Extreme Base Station, and I can't follow the Mac Tutorial, I am using Windows 7 with the Airport Base Station Agent. Thanks in advance!.

    I am just wondering if it's possible to only allow one computer to access Bit Torrent or Limewire connections and leaving out my son for accessing the same things?
    Sorry, but no as the AirPorts do not offer a feature to block P2P communications. It only has the ability to restrict a computer from accessing the Internet at all. Also, most routers that do offer this feature will completely block out the P2P service for all computers ... not just a particular one.

  • Bit Torrent Ports

    Hi,
    I am a new Mac user and have recently purchased a Powerbook G4. I would like to use Bit torrent more efficiently on my Mac.
    I would be greatful to anyone who can guide me on how to allow access to Bit torrent and other applications to specific TCP ports?
    Your help would be highly appreciated!
    Thanks,
    Aditya

    I would be greatful to anyone who can guide me on how
    to allow access to Bit torrent and other applications
    to specific TCP ports?
    Are you behind a router ? If so, you must configure that device to do port forwarding on your Mac to ports 6881-6999.
    To allow the bitTorrent ports through your firewall on OS X:
    System Preferences -> Sharing -> firewall -> new -> other
    Port Number -> 6881-6999
    Port Name -> bittorrent
    OK
    This will allow access to the ports bittorrent uses.

  • Unmappable or stealth port when using Transmission bit torrent

    I'm running transmission bit torrent on my mac right now and I'm getting really slow connections, if any at all.
    I have gone through the port forwarding procedure and it didn't seem to help
    Here is what happens
    I open Transmission and check the advanced preferences, and it says the port is open and successfully mapped. Then, anywhere from 5 minutes onward of the program running the port goes stealth and sometimes is not mappable.
    Help?

    So, you've opened the ports, both TCP and UDP on your Powerbook mac firewall (you have to define an entry to do that on the sharing/firewall preference pane), you don't have 'stop UDP' checked on the sharing/firewall/advance tab, you've defined the same port range on your wireless router in the gaming or port forwarding section, again indicating 'both' instead of just TCP ... correct on those?
    If yes on those steps, have you tried another program besides Transmission? Bittorent is one option at http://download.bittorrent.com/dl/ (stick with one of the early 4.1.n OS X releases, as release 5 is banned on some sites). Or Bits on Wheels at http://www.bitsonwheels.com/ is another that works on OS X.

  • Bit Torrent - won't download on specific computer

    I'm suddenly having issues with bit torrents downloading on my desktop computer.  I have tried multiple programs (deluge, transmission, and my daily use qbittorrent).  I've also tried with a separate user account.  On the same network, my laptop will work just fine (both connected wirelessly), so think its something system-related.  I even tried setting a manual port and port-forwarding via the router.  No matter the tracker it won't connect and just stall out.  I've tried reinstalling (libktorrent libtorrent libtorrent-rasterbar transmission-qt qbittorrent), but nothing seems to affect it.  What am I missing here?

    It's not going to be an issue with port forwarding.  Bittorrent will work even if no ports are forwarded, you'll just see less peers connected.
    You say it can't even connect to the tracker?  That sounds like you have a deeper networking problem not specific to Bittorrent.  I would check your network configuration.  Check your DNS servers, IP address (Make sure no two computers on your network have the same IP address.  That creates a conflict and causes all kinds of nasty and sometimes unpredictable problems), default gateway, and any firewall/iptables configuration you may have.
    Another possibility if other internet applications are working on that machine is that your problem only affects UDP (HTTP web traffic uses TCP.)  A lot of Bittorrent trackers are switching from TCP to UDP.  There's a quick way to test UDP connectivity.  First, install nmap (pacman -S nmap)  Then, as root, run
    nmap -p 60,80 -sU tracker.openbittorrent.com
    This is the expected result:
    Starting Nmap 6.46 ( http://nmap.org ) at 2014-07-10 04:56 CDT
    Nmap scan report for tracker.openbittorrent.com (31.172.63.253)
    Host is up (0.21s latency).
    Other addresses for tracker.openbittorrent.com (not scanned): 31.172.63.252
    PORT STATE SERVICE
    60/udp closed unknown
    80/udp open|filtered http
    Nmap done: 1 IP address (1 host up) scanned in 5.74 seconds
    Note the state of the ports.  The tracker is running on port 80 but since open UDP ports don't send a response back, nmap can't be sure if the port is truly open or if it's being filtered by a firewall.  That's why I also scanned the dummy port 60 so nmap would receive a closed response.  If nmap can differentiate between open and closed ports as demonstrated here, it means you're successfully sending and receiving UDP packets.  If it can't, you've got a deeper networking issue you need to solve.
    Also, if you wish to test a TCP tracker, simply change the -sU to a -sS (and obviously change the ports and hostname since openbittorrent doesn't run a TCP tracker.)

  • Bit torrent app for osx 10.4.11

    What is the best bit torrent app for my g4 running osx 10.4.11??? Thanks in advance.

    Probably Transmission...
    http://www.macupdate.com/info.php/id/19378/transmission
    Or Tomato...
    http://sarwat.net/bittorrent/
    Or...
    http://www.versiontracker.com/dyn/moreinfo/mac/18286

  • Bit torrent downloads

    i want to start by saying that im new to the p2p technology so if my question is dumb i apologize with advance. I just downloaded a movie using bit torrent and i noticed that i came in a different format that i havent seen before (xvid.001...). There are 51 files so i was just wondering if someone could tell how to compress the file so i can watch the movie. i already tried to play them with divx player and i didnt work. I also tried to burn them with toaster as divx disc, and ii didnt work as well
    Thank.

    There are 51 files so i was just wondering if someone could tell how to compress the file
    If a file is split into 50 pieces, that's most likely split with RAR. One of the oldest UnRAR programs for Macs is 'unRarX.' It's reliable and in Universal Binary. But it's a little slow in combining pieces. In this respect, RAR Expander is better and about twice faster. Those two titles are both free.

  • Bit torrent For G4 stuck in 10.4.11

    Anyone have any idea where I could get a torrent program for my G4? Bit torrent apparently doesn't make a version for 10.4.11 any help would be greatly appreciated! Thanks

    Hi-
    Have you tried Transmission?
    https://trac.transmissionbt.com/wiki/PreviousReleases
    It's very good.

  • Using Bit Torrent

    Hello,
    Increasingly I am getting requests from legal site to download their video or Audio content using bit torrent. I have installed the lastest version on my iMac G5 but nothing downloads. Do I need to turn something on or off, I need help please.
    Thank you
    iMac G5   Mac OS X (10.4.6)   1 gig ram

    Hi Brad,
    The more ports you enable for torrents the faster your transfer speeds. Typically you can enable TCP 6881-6999 (range of ports). If you use MacOS X's built-in firewall, follow these steps.
    1. Open System Preferences.
    2. Click Sharing.
    3. Select the Firewall tab.
    4. Click the New... button.
    5. Click the popup menu in the dialog that appears, and choose Other....
    6. In the Port Number, Range, or Series field, enter 6881-6999.
    7. In the Name field, enter BitTorrent (or any other identifying string.)
    8. Click OK.
    If you use any other firewall follow its instructions to enable TCP 6881-6999 (range of ports).
    If you want to understand how it works, you can find a good FAQ&Guide here: http://btfaq.com/serve/cache/1.html
    Macs running 9.x, Macs running 10.4.x, SGI workstations running Irix 6.5.xssion.
    Message was edited by: fu

  • Azareus - Bit Torrent

    I was told this is a good bit torrent for Macs. Does anyone recommend a trustworthy web site to download this application? Also, any pitfalls I should be aware of with this program?
    Thanks,
    McB

    Versiontracker.com is a great place for share/freeware.

  • Bit Torrent

    Can anyone recommend one for the Mac, because the ones that I've used are SO slow for some reason. Should they be?

    Azureus is a nice client. I use it regularly for LEGALLY sharing concert recordings. (I stress LEGAL to avoid the wrath of folks who think that bit torrent is only used for illicit activities. The stuff I share is permitted by the bands themselves, those with taper-friendly policies.)
    Anyway, Azureus regularly gives me upload and download speeds exceeding 200k/second. The trick is to configure the client properly so it isn't hampered by firewalls. Read the documentation and consult online BT sites for further assistance, and I'm sure you'll be pleased with that client.
    Others I've tried have been the official BT client and Tomato Torrent. Both of those are good, too, though I've settled on Azureus due to its extended set of features (such as the ability to grab just one song rather than the entire show.)
    Hope this helps!

  • Bit torrent crashes airport extreme

    Hi, I am currently on my 3rd airport extreme, but the first one was just sold and replaced to upgrade to gigabit. However the second is because Apple sent me a new one. The reason for this is it was continuously crashing and we couldn't figure out why. When I got the new one it didn't take long for it to start crashing too, which is what made me consider everything that was common between the two airports that could cause both to crash and I think I have found it. Its bit torrent. The airport will work perfectly all day long, but if I launch Azureus and start downloading, and I'm only connecting to maybe 4 peers at a time and at about 30kb/sec, the airport will crash within 40 minuets with almost 100 percent certainty. I am curious as to how many people may be able to narrow down their airport crashes to the running of bit torrent.

    I've been struggling (understatement) with this for about 2 weeks now.
    I began back up running a few torrents - very low key, pissy stuff. The internet has been going down as much as 6 times a day. But it's not the AEBS - My modem shuts down as well cuz we tried a computer hardwired to it. Both modem & router needed rebooting. Modem pings fine from the ISP and all modem lights appear fine despite no internet when directly wired to modem. I have Comcast. (sadly)
    So seriously... this fix is working for everyone?
    But fine... why would this all affect the modem itself? Comcasts insists they aren't throttling/shutting me down. Yet, today I've been plugged into the modem directly and the internet blowouts have stopped. Almost like the Extreme was telling the Modem to shut me down.
    Can someone explain how this fix works and the mechanisms as to why it would fix this? I really need to understand this. It's been my full time job for 2 weeks now.

  • Bit torrent not working

    I recently upgraded my iMac to mountain lion, and my bit torrent stopped working.  Why is that?

    Which bit torrent client and have you verified it has a Mountain Lion compatible version?
    Java client?
    Message was edited by: VikingOSX

Maybe you are looking for

  • ApEx 2.1.0.00.39 as Partner Application in Oracle AS Single Sign-On

    Hi, I've installed the last Application Express 2.1.0.00.39 (oracle-xe-10.2.0.1-1.0.i386.rpm and oracle-xe-univ-10.2.0.1-1.0.i386.rpm) but, when I try to "create an authentication scheme" for configure an ApEx application to use SSO under Home>Applic

  • How to apply external CSS file with MyFaces Trinidad?

    In my original JSF page, I used to have <head>     <link href="css/app.css" rel="stylesheet" type="text/css" /> </head>However, after I switched to MyFaces Trinidad and used <tr:document> tag, the external stylesheet could not be applied. <tr:documen

  • Stop sound and start over without "pop"

    I need to be able to interrupt and restart a short (3-4 second) sound file while it's still playing. Seems simple enough, but with both SoundEngine and AudioServices it causing a "popping" sound as it restarts. Is there any way to avoid this? I tried

  • How to set my volume keys to change volume rather than activating narrator

    is there a setting that i can change so that the narrator won't automatically activate when i press the volume button? i'm having windows 8 and i'm not used to it. i'm really getting annoyed that everytime i'm supposed to change the volume it suddenl

  • Patterns Question

    Hey everyone, got a question regarding patterns in Illustrator and this one is sorta bugging me. Basically, I have a single object, a 3 leaf clover. When I import this object into the swatch pallet, it can make a pattern...yet it is more of a x and y