Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


garvani

1873 posts

Uber Geek

Trusted

#19554 21-Feb-2008 14:25
Send private message

Im supervisor of a boarding hostel, we have server 2000 running kerio winroute proxy server, which users must put in the proxy servers address to get the internet. Im trying to stop these highschool kids from wasting bandwidth using limewire, bit torrent etc, which is turning out to be a nightmare!
Kerio dosnt seem to be able to block ports, it lets any traffic through, its pretty damn simple!! its the older version 4, the hostel cant afford to upgrade to version 6 (going to be over $1k to do so)
I have a 3com adsl router (the latest firmware on the router is installed.) which i recently found offers this feature, great i thought so i went and blocked every port except http, smtp, pop3, msn and yahoo messenger.. problem now is that the internet locks up after 10 mins of activity. so it needs to be reset before it will work again, the router hasnt locked up just the internet, is still thinks its connected but isnt. Upon inspecting the logs the router is getting hammered by a port scanner (probably utorrent or limewire looking for a free port), thr router obviously cant handle such things.. so the search continues..

Does anyone know of a decent proxy server or cheap method that will handle blocking thousands of ports, getting port scanned etc. I wouldnt have thought it would be this hard, surely a lot of people have this problem.
Ive looked online but cant find a good method, kerio seemed to be good with handling the internet sharing up until i decided that port blocking needed to be done.  Ive tried usergate and winproxy as well, both dont offer a good enough program.

Here is a snippit of the log, it dosnt really show much i know.. ill post a better one later once i implement the rule again (had to turn it off as too many whiners knocking on my door due to no internet connection

02/20/2008  20:09:39 Reject packet from 192.168.0.2:47392 to 60.28.197.35:28221
02/20/2008  20:09:39 Reject packet from 192.168.0.2:47391 to 58.251.60.66:12000
02/20/2008  20:09:37 Reject packet from 192.168.0.2:47390 to 72.51.37.237:8899
02/20/2008  20:09:25 Reject packet from 192.168.0.2:47389 to 66.199.250.170:8911
02/20/2008  20:09:19 Reject packet from 192.168.0.2:47388 to 219.239.90.172:28221
02/20/2008  20:09:11 Reject packet from 192.168.0.2:47381 to 60.28.197.35:28221
02/20/2008  20:09:09 Reject packet from 192.168.0.2:47378 to 72.51.37.237:8899
02/20/2008  20:08:57 Reject packet from 192.168.0.2:47374 to 66.199.250.170:8911
02/20/2008  20:08:51 Reject packet from 192.168.0.2:47373 to 219.239.90.172:28221
02/20/2008  20:08:43 Reject packet from 192.168.0.2:47372 to 60.28.197.35:28221
02/20/2008  20:08:41 Reject packet from 192.168.0.2:47371 to 72.51.37.237:8899
02/20/2008  20:00:51 Reject packet from 192.168.0.2:47365 to 66.199.250.170:8911
02/20/2008  20:00:45 Reject packet from 192.168.0.2:47363 to 219.239.90.172:28221
02/20/2008  20:00:37 Reject packet from 192.168.0.2:47361 to 60.28.197.35:28221
02/20/2008  20:00:35 Reject packet from 192.168.0.2:47360 to 72.51.37.237:8899
02/20/2008  20:00:33 Reject packet from 192.168.0.2:47359 to 66.199.250.170:8911
02/20/2008  20:00:27 Reject packet from 192.168.0.2:47357 to 219.239.90.172:28221
02/20/2008  20:00:26 Reject packet from 192.168.0.2:47356 to 66.199.250.170:8911
02/20/2008  20:00:26 If(PVC1) PPP connection ok !
02/20/2008  20:00:25 Username and Password: OK
02/20/2008  20:00:19 PVC1 start PPP
02/20/2008  20:00:19 ADSL Media Up !
02/20/2008  20:00:02 WLAN TEST.....................PASS
02/20/2008  20:00:02 WAN ADSL TEST.................PASS

Create new topic
pando
235 posts

Master Geek


  #112092 21-Feb-2008 15:44
Send private message

While not really answering the question, have you told the boarders not to use aforementioned programs with threats of losing access?



coffeebaron
6231 posts

Uber Geek

Trusted
Lifetime subscriber

  #112093 21-Feb-2008 15:46
Send private message

You can contact these guys and see if they can offer a solution:
http://www.watchdog.net.nz/




Rural IT and Broadband support.

 

Broadband troubleshooting and master filter installs.
Starlink installer - one month free: https://www.starlink.com/?referral=RC-32845-88860-71 
Wi-Fi and networking
Cel-Fi supply and installer - boost your mobile phone coverage legally

 

Need help in Auckland, Waikato or BoP? Click my email button, or email me direct: [my user name] at geekzonemail dot com


garvani

1873 posts

Uber Geek

Trusted

  #112098 21-Feb-2008 16:22
Send private message

Unfourtnetly asking them to not do it isnt going to work, they are highschool kids that pay a lot of money to goto the hostel, not allowing them internet access isnt an option, simply telling them not to do it isnt going to cut it, they use there own laptops so monitoring which programs etc is installed is going to be too time consuming and upon me leaving the room they would just restart the program.
The watchdog while an awesome idea isnt for us, i have a web content filtering system in place using opendns. We are on go large plan which is good for us as it gives unlimited data per month, with a decent speed, its just that the connection speed is being sapped from a few users using p2p, and when half the boarders are either chinese, korean, thai or japanese they all want fast internet browsing like they get in there home countrys.



hellonearthisman
1819 posts

Uber Geek

Trusted

  #112099 21-Feb-2008 16:26
Send private message

Block all the ports and the unlock the ports that you support.

I thought Kerio can block programs too.  But that only works on the computer connecting to the net not so good for program packet routing.

Have two BB connections,  one that's throttled and one that's not.  If the room uses > Y data they get put onto the throttled connection and if not, they stay on the fullspeed.

Not sure how that would be done, but it sound good.

garvani

1873 posts

Uber Geek

Trusted

  #112106 21-Feb-2008 16:38
Send private message

I have blocked all the ports and unblocked the ones we need as i explained in the first post. I think the latest version of kerio might block programs (ther version i have certainly doesnt) but as stated again its $1,000+ for it and i can't see the manager paying this. Any other software suggestions is very welcomed!

Two broadband connections isnt really an option either, i would need some sort of traffic management software to monitor how much usage and then flip them over to another connection, too much hard work.

There has to be some simple software solution to stop all traffic (in speciefied rules) on a proxy server before it gets passed to the router.. Thanks for the replys so far.

cyril7
9058 posts

Uber Geek

ID Verified
Trusted
Subscriber

  #112111 21-Feb-2008 17:08
Send private message

Purhaps something a little stronger and more focused on network routing is needed. I am thinking of things like m0n0wall, using it as you NAT router, it also has a powerfull/configurable SPI firewall that might not fall over under load. Should be able to get it running on some old hardware, just reconfigure your ADSL modem into half bridge.

Edit, Possibly using a router like the Linksys WRT54GL with an open source image like DD-WRT or OpenWRT would provide a more powerfull and configurable router, again you would need to get an ADSL modem in bridge to work with an external router like this.


Cyril

hellonearthisman
1819 posts

Uber Geek

Trusted

  #112497 23-Feb-2008 16:26
Send private message

I was randomly trying to fide the artical I saw artical I saw last week, but came across this.

http://www.ghacks.net/2008/02/22/limit-upload-and-download-bandwidth/
Traffic Shaper XP [rediscovered at Raymond.CC] comes to the rescue. Users can restrict the upload and download bandwidth of certain ports and protocols on their systems. That’s right, it is not application based but that is not a huge problem normally unless you randomly select ports in your applications or use applications that do that by themselves.
And throught it may be of use.

 
 
 

Cloud spending continues to surge globally, but most organisations haven’t made the changes necessary to maximise the value and cost-efficiency benefits of their cloud investments. Download the whitepaper From Overspend to Advantage now.
kingoe
25 posts

Geek


  #112625 24-Feb-2008 10:58

I would use a firewall (software based) with password protection first of all, so the kids can't change what ports blocked etc at the software level.

Also change the router/modem's login web interface password, so dlink is admin/admin by default, change the port number on it too.
This will prevent the kids messing around with this interface.
In addition to what others on this thread have already said, a very old fashioned way is to do these two things:

1) Open Device Manager, this will work if using a Network Card not USB/Wireless. In device manager select the properties of your Net. Card, you can change in here the flow rate/speed so from 10/100Mbps down - thats if your using a local based proxy over LAN behind DMZ.

or
2) Packet Filtering in your Local Area Connection. Select properties of your Local Area Connection (In Net Connections), then the properties of Internet Protocol (TCP/IP) - IPv4 if on Vista.
Once here click the advanced button, click the options tab, then lastly properties button for TCP/IP filtering.
In here you can contron TCP, UDP ports as well as IP protocols.

If these don't work get a better software firewall with password protection builtin and possibly the use of group policy if available to prevent changes to the LAN etc.

I see where cyril7 is going, bridge mode is also a good option. Another router to try with good config's is the NetGear NB5 and Cisco ADSL 4 port NAT/Firewall builtin - i cant remember the model number but its the commonly known blue and black one which won a few awards.

barf
643 posts

Ultimate Geek


  #112633 24-Feb-2008 11:19

I agree with cyril  suggestion to replace firewall. I reccomend pfsense (which is actually an evolution of m0n0wall code)

using pfsense web-based configuration (like setting up a d-link on steroids) you can limit speed of all protocols other than port-80 http and et cetera.




Sniffing the glue holding the Internet together

garvani

1873 posts

Uber Geek

Trusted

  #112849 25-Feb-2008 10:02
Send private message

Cheers Cryill and Barf, thats basically what i was looking for.. Will test this out sometime over the next week and let you know how i get on.

Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.