<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[How to know if someone is using torrent in my network??]]></title><description><![CDATA[<p dir="auto">Hey,<br />
Can anyone tell me how to check if someone is downloading anything from torrent or other things via p2p clients..<br />
I have installed squidguard and sarg in my PFSense server machine but I'm unable to know who is downloading via torrent, p2p clients.</p>
]]></description><link>https://forum.netgate.com/topic/83358/how-to-know-if-someone-is-using-torrent-in-my-network</link><generator>RSS for Node</generator><lastBuildDate>Wed, 17 Jun 2026 13:15:38 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/83358.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 26 Apr 2015 06:41:09 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to How to know if someone is using torrent in my network?? on Mon, 27 Apr 2015 14:52:16 GMT]]></title><description><![CDATA[<p dir="auto">Shut down your outbound ports and see how much you upload to peers that listen all kinds of random ports.</p>
]]></description><link>https://forum.netgate.com/post/540165</link><guid isPermaLink="true">https://forum.netgate.com/post/540165</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Mon, 27 Apr 2015 14:52:16 GMT</pubDate></item><item><title><![CDATA[Reply to How to know if someone is using torrent in my network?? on Mon, 27 Apr 2015 14:05:27 GMT]]></title><description><![CDATA[<p dir="auto">I must be having a different Transmission client than you all  ;D</p>
<ul>
<li>
<p dir="auto">I have no ports open on WAN;</p>
</li>
<li>
<p dir="auto">I have no ports forwarded;</p>
</li>
<li>
<p dir="auto">I easily seed 500% per torrent;</p>
</li>
</ul>
<p dir="auto">That aside, if you set your client port to port 80 you'll circumvent any measure with allowed ports too.</p>
<p dir="auto">Imho either snort to block it, or traffic shaper to limit the speed to zero.</p>
<p dir="auto">(I'd go for Snort; set it, and forget it, instead of wasting time again and again because you have to sniff if somebody might be torrenting).</p>
]]></description><link>https://forum.netgate.com/post/540155</link><guid isPermaLink="true">https://forum.netgate.com/post/540155</guid><dc:creator><![CDATA[Mr. Jingles]]></dc:creator><pubDate>Mon, 27 Apr 2015 14:05:27 GMT</pubDate></item><item><title><![CDATA[Reply to How to know if someone is using torrent in my network?? on Mon, 27 Apr 2015 12:06:36 GMT]]></title><description><![CDATA[<p dir="auto">Agreed, p2p hard to work when only port 80 and 443 outbound is allowed ;)  With no inbound ports - sure they might be able to be able to get to a few seeds, but they sure wouldn't be uploading anything.</p>
<p dir="auto">As to how it looks in a sniff, I don't run any p2p locally anyway - its all via a seedbox.  But sure if I get a chance will fire up a sniff there to show how it looks.. Simple look and you will see it – its very distinct and easy to spot traffic.</p>
<p dir="auto">As to why would you have to look at it tmrw.. You shut down a few users with warning letters from management, and the rest of the user base follows suite very quickly in not doing it.</p>
]]></description><link>https://forum.netgate.com/post/540122</link><guid isPermaLink="true">https://forum.netgate.com/post/540122</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Mon, 27 Apr 2015 12:06:36 GMT</pubDate></item><item><title><![CDATA[Reply to How to know if someone is using torrent in my network?? on Mon, 27 Apr 2015 11:12:09 GMT]]></title><description><![CDATA[<p dir="auto">The only good way to mostly stop torrents is to block all incoming ports, no port forwarding, and limit outgoing ports. If all you care about is web pages, then this should work, I think.</p>
]]></description><link>https://forum.netgate.com/post/540116</link><guid isPermaLink="true">https://forum.netgate.com/post/540116</guid><dc:creator><![CDATA[Harvy66]]></dc:creator><pubDate>Mon, 27 Apr 2015 11:12:09 GMT</pubDate></item><item><title><![CDATA[Reply to How to know if someone is using torrent in my network?? on Mon, 27 Apr 2015 04:24:44 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a>:</p>
<blockquote>
<p dir="auto">why don't you just take a simple sniff for a few minutes and look at the traffic - it will very simple to spot p2p traffic.</p>
</blockquote>
<p dir="auto">but how to check p2p log?</p>
]]></description><link>https://forum.netgate.com/post/540029</link><guid isPermaLink="true">https://forum.netgate.com/post/540029</guid><dc:creator><![CDATA[pankajpomal]]></dc:creator><pubDate>Mon, 27 Apr 2015 04:24:44 GMT</pubDate></item><item><title><![CDATA[Reply to How to know if someone is using torrent in my network?? on Sun, 26 Apr 2015 19:18:36 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a>:</p>
<blockquote>
<p dir="auto">why don't you just take a simple sniff for a few minutes and look at the traffic - it will very simple to spot p2p traffic.</p>
</blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/doktornotor">@<bdi>doktornotor</bdi></a>:</p>
<blockquote>
<p dir="auto">Not even sniff needed. If you look at the firewall states, it's extremely obvious.</p>
</blockquote>
<p dir="auto">DHCP: the next day you'll have to sniff another thing.</p>
<p dir="auto">(Yes, we economists, we're stupid with our thing about efficiency  ;D ).</p>
]]></description><link>https://forum.netgate.com/post/539963</link><guid isPermaLink="true">https://forum.netgate.com/post/539963</guid><dc:creator><![CDATA[Mr. Jingles]]></dc:creator><pubDate>Sun, 26 Apr 2015 19:18:36 GMT</pubDate></item><item><title><![CDATA[Reply to How to know if someone is using torrent in my network?? on Sun, 26 Apr 2015 15:13:06 GMT]]></title><description><![CDATA[<p dir="auto">This is how I know when I'm torrenting. But really, most torrent clients use random ports for nearly everything, some even randomly change ports over time, and they use a mixture of UDP and TCP traffic, all encrypted. Your only hope would be to block all encrypted traffic. But you can slow down torrent or look for torrent by monitoring the default torrent ports, but that will mostly get you stuff like Blizzard's Battle.Net launcher.</p>
<p dir="auto"><img src="https://lh4.googleusercontent.com/-kdZxKRvbz3w/VTz22yrhJOI/AAAAAAAADWM/pM2l_uuIvzE/w762-h483-no/Debian8.png" alt="" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/539918</link><guid isPermaLink="true">https://forum.netgate.com/post/539918</guid><dc:creator><![CDATA[Harvy66]]></dc:creator><pubDate>Sun, 26 Apr 2015 15:13:06 GMT</pubDate></item><item><title><![CDATA[Reply to How to know if someone is using torrent in my network?? on Sun, 26 Apr 2015 14:15:04 GMT]]></title><description><![CDATA[<p dir="auto">Unsure whether it's worse to get DoSed by BT or by Snort… :P</p>
]]></description><link>https://forum.netgate.com/post/539915</link><guid isPermaLink="true">https://forum.netgate.com/post/539915</guid><dc:creator><![CDATA[doktornotor]]></dc:creator><pubDate>Sun, 26 Apr 2015 14:15:04 GMT</pubDate></item><item><title><![CDATA[Reply to How to know if someone is using torrent in my network?? on Sun, 26 Apr 2015 13:32:39 GMT]]></title><description><![CDATA[<p dir="auto">A shout-out to Dustin Webber for his Snorby project. I use it as a front-end for my Snort-IDS to display the payload for P2P traffic in the database.</p>
]]></description><link>https://forum.netgate.com/post/539910</link><guid isPermaLink="true">https://forum.netgate.com/post/539910</guid><dc:creator><![CDATA[gjaltemba]]></dc:creator><pubDate>Sun, 26 Apr 2015 13:32:39 GMT</pubDate></item><item><title><![CDATA[Reply to How to know if someone is using torrent in my network?? on Sun, 26 Apr 2015 11:40:23 GMT]]></title><description><![CDATA[<p dir="auto">This is very true as well ;)  I just like to see the actual traffic..</p>
]]></description><link>https://forum.netgate.com/post/539892</link><guid isPermaLink="true">https://forum.netgate.com/post/539892</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Sun, 26 Apr 2015 11:40:23 GMT</pubDate></item><item><title><![CDATA[Reply to How to know if someone is using torrent in my network?? on Sun, 26 Apr 2015 11:30:28 GMT]]></title><description><![CDATA[<p dir="auto">Not even sniff needed. If you look at the firewall states, it's extremely obvious.</p>
]]></description><link>https://forum.netgate.com/post/539891</link><guid isPermaLink="true">https://forum.netgate.com/post/539891</guid><dc:creator><![CDATA[doktornotor]]></dc:creator><pubDate>Sun, 26 Apr 2015 11:30:28 GMT</pubDate></item><item><title><![CDATA[Reply to How to know if someone is using torrent in my network?? on Sun, 26 Apr 2015 11:08:21 GMT]]></title><description><![CDATA[<p dir="auto">why don't you just take a simple sniff for a few minutes and look at the traffic - it will very simple to spot p2p traffic.</p>
]]></description><link>https://forum.netgate.com/post/539886</link><guid isPermaLink="true">https://forum.netgate.com/post/539886</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Sun, 26 Apr 2015 11:08:21 GMT</pubDate></item><item><title><![CDATA[Reply to How to know if someone is using torrent in my network?? on Sun, 26 Apr 2015 07:55:45 GMT]]></title><description><![CDATA[<p dir="auto">Install Snort and let it block it?</p>
]]></description><link>https://forum.netgate.com/post/539862</link><guid isPermaLink="true">https://forum.netgate.com/post/539862</guid><dc:creator><![CDATA[Mr. Jingles]]></dc:creator><pubDate>Sun, 26 Apr 2015 07:55:45 GMT</pubDate></item></channel></rss>