| To: | "Roberto Pereyra" <pereyra.roberto@gmail.com>, lartc@mailman.ds9a.nl |
|---|---|
| Subject: | Re: [LARTC] bridge and ipp2p question |
| From: | "Marco Aurelio" <marco.casaroli@gmail.com> |
| Date: | Thu, 18 Jan 2007 12:55:55 -0300 |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | lartc-list@securepoint.com |
| Delivered-to: | lartc@outpost.ds9a.nl |
| Domainkey-signature: | a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:to:subject:in-reply-to:mime-version:content-type:references; b=UKFoFt22UEsf1CGrVjx1TLxMnO0Et7O784EAfk4w0uXX02f25g49bhXFvaN1IQAdtCW0RRIbXwvCdFxKOQDsvZm9IeUJVJgpz+dt0zw3vxtq83luq9Igi9Jg/ZLCOfar5jrmQWV57VYjbJmm8/JN2l2dGereVH585rsNjVpnoYw= |
| In-reply-to: | <f05666f00701170312y3a8b7451t6a0d2726379cc5da@mail.gmail.com> |
| List-archive: | <http://mailman.ds9a.nl/pipermail/lartc> |
| List-help: | <mailto:lartc-request@mailman.ds9a.nl?subject=help> |
| List-id: | "Mailinglist of the Linux Advanced Routing & Traffic Control project" <lartc.mailman.ds9a.nl> |
| List-post: | <mailto:lartc@mailman.ds9a.nl> |
| List-subscribe: | <http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc>, <mailto:lartc-request@mailman.ds9a.nl?subject=subscribe> |
| List-unsubscribe: | <http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc>, <mailto:lartc-request@mailman.ds9a.nl?subject=unsubscribe> |
| References: | <f05666f00701170312y3a8b7451t6a0d2726379cc5da@mail.gmail.com> |
| Sender: | lartc-bounces@mailman.ds9a.nl |
|
This is not possible because ipp2p does not match every p2p packet but
only some essential signaling packets. By filtering these packets, the
p2p client cannot estabilish connections to transfer data, and that's
how it filters it. Sometimes, ipp2p 'discovers' that this is a p2p related connection after the connection has been established, and then drops the signaling packets. And since you are not an AS and you have one different address per connection, you cannot route packets with a different source address than the one the connection has been established. I have a different approach on this, it is not a perfect soulution, but it work quite well on some enviroments: I route all the traffic through one NIC (the garbage p2p connection) and then (with iptables or u32) direct the important traffic by port (HTTP, FTP, IRC, MSN, DNS, SMTP, POP, etc) through the other NIC (the non-p2p connection). Then I filter (with ipp2p) the p2p traffic on the non-p2p NIC because some p2p clients try to mask the connections as it were these services. This works quite well, but you need to know every service your clients use. I use this on a router, I never tested this with a bridge, but it may work too. -- Marco On 1/17/07, Roberto Pereyra <pereyra.roberto@gmail.com> wrote: Hi all !!! -- Marco _______________________________________________ LARTC mailing list LARTC@mailman.ds9a.nl http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [LARTC] Validating QoS, lee nookx |
|---|---|
| Next by Date: | RE: [LARTC] IPP2P Problem, Rangi Biddle |
| Previous by Thread: | [LARTC] bridge and ipp2p question, Roberto Pereyra |
| Next by Thread: | Re: [LARTC] bridge and ipp2p question, Roberto Pereyra |
| Indexes: | [Date] [Thread] [Top] [All Lists] |