Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    how to block bad guys who is sharing internet by laptop

    Scheduled Pinned Locked Moved General pfSense Questions
    18 Posts 6 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      begaa @johnpoz
      last edited by

      @johnpoz
      we are small construction company and i am new at pfsense, i thinked that may be there have something new to solve this problem, i can create on that laptops user accounts and control them, but that laptops are their personal so need to search another way...

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        There's no practical way to do that in pfSense.

        You could potentially make it very painful for users doing that. Maybe limit the number of connections or rate of connection to individual IPs. Or limit bandwidth to each IP.

        We have seen people using schemes such as re-writing the TTL on packets to prevent routing but that is not something pfSense does (as standard).

        Steve

        B 1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by johnpoz

          Still not understanding why this is an issue, and why are they doing it in the first place?

          So you have a user that has their own device, that gets on your wifi network... And this user works for you.. Why are they sharing out the internet - and to who? Other workers that are not suppose to have it... Random people on the street?

          What are they doing that you want to stop? Are they using up all your bandwidth?

          Why do you not want them doing this? There not much you can do to stop it though to be honest.. Just like isp that sells you internet can not keep that person from sharing it with everyone on the block, etc. if that person wanted too..

          Detecting nat and then blocking it it pretty high level stuff.. Simple way is to look for ttl that has gone through a hop already... But If you are doing that and block that, I can just make sure my nat doesn't change the ttl from default, etc.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          B 1 Reply Last reply Reply Quote 0
          • M
            marvosa
            last edited by

            The question I'd have is... what's your main concern? If it's bandwidth, then configure QoS.

            Otherwise, there's no viable way to do what you're asking. Just like there's no viable way for your ISP to block the 50+ devices you have behind PFsense.

            1 Reply Last reply Reply Quote 0
            • B
              begaa @stephenw10
              last edited by

              @stephenw10
              yes i understand, need to search another way

              1 Reply Last reply Reply Quote 0
              • B
                begaa @johnpoz
                last edited by

                @johnpoz
                internet speed is small (10M/bit for 50 person), it need to control users bandwitdth and internet usage, so need to make office staff can use normal speed.
                If there is no way to solve i will give limit per ip, i think it will keep traffic normal

                Thanks a lot to everybody!!!

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by johnpoz

                  @begaa said in how to block bad guys who is sharing internet by laptop:

                  (10M/bit for 50 person)

                  That is not viable - just have them hotspot off their phones for gosh sake.. That is isn't even internet..

                  200K that is what you would give each IP? That is like a edge connection (2g)..

                  I could hostspot off my phone for your 50 users and give them better speeds ;)

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    You can use dynamic Limiters to ensure the available bandwidth is shared equally. That can work quite well in these situations.

                    Steve

                    JKnottJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      10mbps though... You can get that on a plane ;) while its flying.. ATG-4 does 9.8Mbps - and your normally sharing it with far fewer people than 50 ;) since not everyone is paying and using it...

                      And if newer plane doing 2ku

                      Are you in the middle of nowhere? Not sure how you thought sharing 10mbps with 50 people would be worth anything? Did you drop a zero did you mean 100? ;)

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        Ha. There are, unfortunately, still plenty of people even here in the UK who would kill for 10Mbps. I imagine there are other places in the world where far less than that is expected.

                        Steve

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          But to share that with 50 people? Come on - that is not realistic... Unless you were in the middle of freaking nowhere..

                          Fire up a 4G/LTE hotspot and you have more than 10mbps... The UK is pretty freaking small ;) What like half the size of California... Your telling me you can not get 10mbps LTE pretty much anywhere?

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          M 1 Reply Last reply Reply Quote 0
                          • JKnottJ
                            JKnott @stephenw10
                            last edited by

                            @stephenw10 said in how to block bad guys who is sharing internet by laptop:

                            You can use dynamic Limiters to ensure the available bandwidth is shared equally.

                            Or maybe throttle the users. ๐Ÿ˜‰

                            PfSense running on Qotom mini PC
                            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                            UniFi AC-Lite access point

                            I haven't lost my mind. It's around here...somewhere...

                            1 Reply Last reply Reply Quote 0
                            • M
                              marvosa @johnpoz
                              last edited by

                              @johnpoz said in how to block bad guys who is sharing internet by laptop:

                              But to share that with 50 people? Come on - that is not realistic... Unless you were in the middle of freaking nowhere..
                              Fire up a 4G/LTE hotspot and you have more than 10mbps... The UK is pretty freaking small ;) What like half the size of California... Your telling me you can not get 10mbps LTE pretty much anywhere?

                              It's certainly not ideal, but in certain circumstances, that's all you have. I work for a healthcare org that has 120+ sites. While our data centers have dual gigabit, several of the clinics are indeed sharing a 10 Mbit or even 5 Mbit MOE circuit. We even have a few clinics that are sharing a single T1... it's insane, but real... unfortunately.

                              JKnottJ 1 Reply Last reply Reply Quote 0
                              • johnpozJ
                                johnpoz LAYER 8 Global Moderator
                                last edited by johnpoz

                                @marvosa said in how to block bad guys who is sharing internet by laptop:

                                We even have a few clinics that are sharing a single T1

                                And your saying that is the only thing available - these clinics in the congo 300 miles from the nearest village? Bringing medicine to the natives?

                                Or company too cheap to pay for anything better.. I would think even the cheapest home internet connection in the area would be better than a freaking T1 ;)

                                There is no cell coverage in the area? Cradlepoint and a sim card would be faster than a any of those speeds.

                                An intelligent man is sometimes forced to be drunk to spend time with his fools
                                If you get confused: Listen to the Music Play
                                Please don't Chat/PM me for help, unless mod related
                                SG-4860 24.11 | Lab VMs 2.8, 24.11

                                1 Reply Last reply Reply Quote 0
                                • JKnottJ
                                  JKnott @marvosa
                                  last edited by JKnott

                                  @marvosa said in how to block bad guys who is sharing internet by laptop:

                                  We even have a few clinics that are sharing a single T1...

                                  A real T1? These days, those are generally emulated over Ethernet. I first did that over 10 years ago. They have also been run over SHDSL for many years. I was working with that stuff back in the early '90s.

                                  I suppose there are still some parts of the world that rely on 2 cans and a string. ๐Ÿ˜‰

                                  PfSense running on Qotom mini PC
                                  i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                                  UniFi AC-Lite access point

                                  I haven't lost my mind. It's around here...somewhere...

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.