Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to block torrent traffic on pfSense ?

    Traffic Shaping
    9
    10
    54.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      Munis
      last edited by

      Hi,  I'm pfsense beginer user,I had installed pfSnse 2.0.1 in university and speed of Internet is too low and I need to block torrent traffic. Could you tell me how to block torrent traffic in pfSense with(SquidGuard or squid)
      Thanks !! ???

      1 Reply Last reply Reply Quote 0
      • N
        Nachtfalke
        last edited by

        It is really hard if not to say nearly impossible to block torrent. You can block .torrent files in squidguard or torrent pages.
        The Layer7 option to block torrent isn't working because torrent traffic is often encrypted and cannot be blocked.

        Perhaps you should think about another posibility - not to block the bad traffic but to priorize the good traffic.
        You can create shaper/limiters which allow high priority for well known traffic like DNS, http, https and limit all other traffic to a very low bandwidth.

        1 Reply Last reply Reply Quote 0
        • marcellocM
          marcelloc
          last edited by

          A close firewall setup + squidguard/dansguardian to filter http + allow only know ssl sites can do a good job on torrent fight.

          Treinamentos de Elite: http://sys-squad.com

          Help a community developer! ;D

          1 Reply Last reply Reply Quote 1
          • Y
            yeeah39
            last edited by

            you can use vpn to unblock .

            1 Reply Last reply Reply Quote 0
            • knight-of-niK
              knight-of-ni
              last edited by

              Loading the p2p rules in Snort works for me.
              You can choose to block source and/or destination ip.

              1 Reply Last reply Reply Quote 0
              • M
                mibovrd
                last edited by

                Snort seems to work for me too. With Snort and Emerging Threats p2p enabled.

                Tweet: MIBovrd@cqrite http://www.cqrite.com

                1 Reply Last reply Reply Quote 0
                • D
                  dhatz
                  last edited by

                  Snort would be an option, however blocking the "offending" IP altogether seems a bit too drastic for some environments. Ideally one should be able to simply drop P2P connections …

                  One idea that comes to mind is to have Snort "tag" (mark) certain connections as P2P and then be able to drop those connections in the firewall rules: block in log all tag $snort-p2p

                  I have to check whether Ermal's recent improvements to spoink/Snort (see https://github.com/bsdperimeter/pfsense-tools/tree/master/pfPorts/snort/files) allows tagging …

                  1 Reply Last reply Reply Quote 0
                  • Y
                    yeeah39
                    last edited by

                    use proxy or vpn will be better

                    1 Reply Last reply Reply Quote 0
                    • C
                      Cino
                      last edited by

                      @yeeah39:

                      use proxy or vpn will be better

                      they are trying to block the traffic, not find a way around it… With a close fw, only allowing the ports to you.. Makes it hard to use an external proxy and vpn... unless they use a port that you have open for internet access.

                      1 Reply Last reply Reply Quote 0
                      • E
                        eri--
                        last edited by

                        The snort tagging would be only useful if snort is put inline.
                        Furthermore the encryption of torrent will just make it impossible for snort as well to detect it.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.