Kerio Tech Firewall6 Network Router User Manual


 
213
Chapter 15
Advanced security features
15.1 P2P Eliminator
Peer-to-Peer (P2P) networks are world-wide distributed systems, where each node can
represent both a client and a server. These networks are used for sharing of big volumes
of data (this sharing is mostly illegal). DirectConnect and Kazaa are the most popular
ones.
In addition to illegal data distribution, utilization of P2P networks overload lines via
which users are connected to the Internet. Such users may limit connections of other
users in the same network and may increase costs for the line (for example when volume
of transmitted data is limited for the line).
WinRoute provides the P2P Eliminator module which detects connections to P2P net-
works and applies specific restrictions. Since there is a large variety of P2P networks and
parameters at individual nodes (servers, number of connections, etc.) can be changed,
it is hardly possible to detect all P2P connections.
5
. However, using various methods
(such as known ports, established connections, etc.), the P2P Eliminator is able to detect
whether a user connects to one or multiple P2P networks.
The following restrictions can be applied to users of P2P networks (i.e. to hosts on which
clients of such networks are run):
Blocking options it is possible to block access to the Internet for a particular host
or to restrict the access only to selected services (e.g. web and e-mail),
Bandwidth limitation it is possible to decrease speed of data transmission of P2P
clients so that other users are not affected by too much data transferred by the line.
P2P Eliminator Configuration
P2P networks are detected automatically (the P2P Eliminator module keeps running).
To set the P2P Eliminator module’s parameters, go to the P2P Eliminator tab in the
Configuration Advanced Options section.
According to thorough tests, the detection is highly reliable (probability of failure is very low).
5