Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


garvani

1873 posts

Uber Geek
+1 received by user: 83

Trusted

#19554 21-Feb-2008 14:25
Send private message

Im supervisor of a boarding hostel, we have server 2000 running kerio winroute proxy server, which users must put in the proxy servers address to get the internet. Im trying to stop these highschool kids from wasting bandwidth using limewire, bit torrent etc, which is turning out to be a nightmare!
Kerio dosnt seem to be able to block ports, it lets any traffic through, its pretty damn simple!! its the older version 4, the hostel cant afford to upgrade to version 6 (going to be over $1k to do so)
I have a 3com adsl router (the latest firmware on the router is installed.) which i recently found offers this feature, great i thought so i went and blocked every port except http, smtp, pop3, msn and yahoo messenger.. problem now is that the internet locks up after 10 mins of activity. so it needs to be reset before it will work again, the router hasnt locked up just the internet, is still thinks its connected but isnt. Upon inspecting the logs the router is getting hammered by a port scanner (probably utorrent or limewire looking for a free port), thr router obviously cant handle such things.. so the search continues..

Does anyone know of a decent proxy server or cheap method that will handle blocking thousands of ports, getting port scanned etc. I wouldnt have thought it would be this hard, surely a lot of people have this problem.
Ive looked online but cant find a good method, kerio seemed to be good with handling the internet sharing up until i decided that port blocking needed to be done.  Ive tried usergate and winproxy as well, both dont offer a good enough program.

Here is a snippit of the log, it dosnt really show much i know.. ill post a better one later once i implement the rule again (had to turn it off as too many whiners knocking on my door due to no internet connection

02/20/2008  20:09:39 Reject packet from 192.168.0.2:47392 to 60.28.197.35:28221
02/20/2008  20:09:39 Reject packet from 192.168.0.2:47391 to 58.251.60.66:12000
02/20/2008  20:09:37 Reject packet from 192.168.0.2:47390 to 72.51.37.237:8899
02/20/2008  20:09:25 Reject packet from 192.168.0.2:47389 to 66.199.250.170:8911
02/20/2008  20:09:19 Reject packet from 192.168.0.2:47388 to 219.239.90.172:28221
02/20/2008  20:09:11 Reject packet from 192.168.0.2:47381 to 60.28.197.35:28221
02/20/2008  20:09:09 Reject packet from 192.168.0.2:47378 to 72.51.37.237:8899
02/20/2008  20:08:57 Reject packet from 192.168.0.2:47374 to 66.199.250.170:8911
02/20/2008  20:08:51 Reject packet from 192.168.0.2:47373 to 219.239.90.172:28221
02/20/2008  20:08:43 Reject packet from 192.168.0.2:47372 to 60.28.197.35:28221
02/20/2008  20:08:41 Reject packet from 192.168.0.2:47371 to 72.51.37.237:8899
02/20/2008  20:00:51 Reject packet from 192.168.0.2:47365 to 66.199.250.170:8911
02/20/2008  20:00:45 Reject packet from 192.168.0.2:47363 to 219.239.90.172:28221
02/20/2008  20:00:37 Reject packet from 192.168.0.2:47361 to 60.28.197.35:28221
02/20/2008  20:00:35 Reject packet from 192.168.0.2:47360 to 72.51.37.237:8899
02/20/2008  20:00:33 Reject packet from 192.168.0.2:47359 to 66.199.250.170:8911
02/20/2008  20:00:27 Reject packet from 192.168.0.2:47357 to 219.239.90.172:28221
02/20/2008  20:00:26 Reject packet from 192.168.0.2:47356 to 66.199.250.170:8911
02/20/2008  20:00:26 If(PVC1) PPP connection ok !
02/20/2008  20:00:25 Username and Password: OK
02/20/2008  20:00:19 PVC1 start PPP
02/20/2008  20:00:19 ADSL Media Up !
02/20/2008  20:00:02 WLAN TEST.....................PASS
02/20/2008  20:00:02 WAN ADSL TEST.................PASS

Create new topic
pando
235 posts

Master Geek


  #112092 21-Feb-2008 15:44
Send private message

While not really answering the question, have you told the boarders not to use aforementioned programs with threats of losing access?



coffeebaron
6304 posts

Uber Geek
+1 received by user: 3566

Trusted
Lifetime subscriber

  #112093 21-Feb-2008 15:46
Send private message

You can contact these guys and see if they can offer a solution:
http://www.watchdog.net.nz/




Rural IT and Broadband support.

 

Broadband troubleshooting and master filter installs.
Starlink installer - one month free: https://www.starlink.com/?referral=RC-32845-88860-71 
Wi-Fi and networking
Cel-Fi supply and installer - boost your mobile phone coverage legally

 

Need help in Auckland, Waikato or BoP? Click my email button, or email me direct: [my user name] at geekzonemail dot com


garvani

1873 posts

Uber Geek
+1 received by user: 83

Trusted

  #112098 21-Feb-2008 16:22
Send private message

Unfourtnetly asking them to not do it isnt going to work, they are highschool kids that pay a lot of money to goto the hostel, not allowing them internet access isnt an option, simply telling them not to do it isnt going to cut it, they use there own laptops so monitoring which programs etc is installed is going to be too time consuming and upon me leaving the room they would just restart the program.
The watchdog while an awesome idea isnt for us, i have a web content filtering system in place using opendns. We are on go large plan which is good for us as it gives unlimited data per month, with a decent speed, its just that the connection speed is being sapped from a few users using p2p, and when half the boarders are either chinese, korean, thai or japanese they all want fast internet browsing like they get in there home countrys.



hellonearthisman
1819 posts

Uber Geek
+1 received by user: 52

Trusted

  #112099 21-Feb-2008 16:26
Send private message

Block all the ports and the unlock the ports that you support.

I thought Kerio can block programs too.  But that only works on the computer connecting to the net not so good for program packet routing.

Have two BB connections,  one that's throttled and one that's not.  If the room uses > Y data they get put onto the throttled connection and if not, they stay on the fullspeed.

Not sure how that would be done, but it sound good.

garvani

1873 posts

Uber Geek
+1 received by user: 83

Trusted

  #112106 21-Feb-2008 16:38
Send private message

I have blocked all the ports and unblocked the ones we need as i explained in the first post. I think the latest version of kerio might block programs (ther version i have certainly doesnt) but as stated again its $1,000+ for it and i can't see the manager paying this. Any other software suggestions is very welcomed!

Two broadband connections isnt really an option either, i would need some sort of traffic management software to monitor how much usage and then flip them over to another connection, too much hard work.

There has to be some simple software solution to stop all traffic (in speciefied rules) on a proxy server before it gets passed to the router.. Thanks for the replys so far.

cyril7
9073 posts

Uber Geek
+1 received by user: 2499

ID Verified
Trusted
Subscriber

  #112111 21-Feb-2008 17:08
Send private message

Purhaps something a little stronger and more focused on network routing is needed. I am thinking of things like m0n0wall, using it as you NAT router, it also has a powerfull/configurable SPI firewall that might not fall over under load. Should be able to get it running on some old hardware, just reconfigure your ADSL modem into half bridge.

Edit, Possibly using a router like the Linksys WRT54GL with an open source image like DD-WRT or OpenWRT would provide a more powerfull and configurable router, again you would need to get an ADSL modem in bridge to work with an external router like this.


Cyril

 
 
 
 

Shop now on Samsung phones, tablets, TVs and more (affiliate link).
hellonearthisman
1819 posts

Uber Geek
+1 received by user: 52

Trusted

  #112497 23-Feb-2008 16:26
Send private message

I was randomly trying to fide the artical I saw artical I saw last week, but came across this.

http://www.ghacks.net/2008/02/22/limit-upload-and-download-bandwidth/
Traffic Shaper XP [rediscovered at Raymond.CC] comes to the rescue. Users can restrict the upload and download bandwidth of certain ports and protocols on their systems. That’s right, it is not application based but that is not a huge problem normally unless you randomly select ports in your applications or use applications that do that by themselves.
And throught it may be of use.

kingoe
25 posts

Geek


  #112625 24-Feb-2008 10:58

I would use a firewall (software based) with password protection first of all, so the kids can't change what ports blocked etc at the software level.

Also change the router/modem's login web interface password, so dlink is admin/admin by default, change the port number on it too.
This will prevent the kids messing around with this interface.
In addition to what others on this thread have already said, a very old fashioned way is to do these two things:

1) Open Device Manager, this will work if using a Network Card not USB/Wireless. In device manager select the properties of your Net. Card, you can change in here the flow rate/speed so from 10/100Mbps down - thats if your using a local based proxy over LAN behind DMZ.

or
2) Packet Filtering in your Local Area Connection. Select properties of your Local Area Connection (In Net Connections), then the properties of Internet Protocol (TCP/IP) - IPv4 if on Vista.
Once here click the advanced button, click the options tab, then lastly properties button for TCP/IP filtering.
In here you can contron TCP, UDP ports as well as IP protocols.

If these don't work get a better software firewall with password protection builtin and possibly the use of group policy if available to prevent changes to the LAN etc.

I see where cyril7 is going, bridge mode is also a good option. Another router to try with good config's is the NetGear NB5 and Cisco ADSL 4 port NAT/Firewall builtin - i cant remember the model number but its the commonly known blue and black one which won a few awards.

barf
643 posts

Ultimate Geek


  #112633 24-Feb-2008 11:19

I agree with cyril  suggestion to replace firewall. I reccomend pfsense (which is actually an evolution of m0n0wall code)

using pfsense web-based configuration (like setting up a d-link on steroids) you can limit speed of all protocols other than port-80 http and et cetera.




Sniffing the glue holding the Internet together

garvani

1873 posts

Uber Geek
+1 received by user: 83

Trusted

  #112849 25-Feb-2008 10:02
Send private message

Cheers Cryill and Barf, thats basically what i was looking for.. Will test this out sometime over the next week and let you know how i get on.

Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.