<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: How to universally disallow P2P?</title>
	<link>http://ask.metafilter.com/30338/How-to-universally-disallow-P2P/</link>
	<description>Comments on Ask MetaFilter post How to universally disallow P2P?</description>
	<pubDate>Fri, 06 Jan 2006 13:20:19 -0800</pubDate>
	<lastBuildDate>Fri, 06 Jan 2006 13:20:19 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Question: How to universally disallow P2P?</title>
		<link>http://ask.metafilter.com/30338/How-to-universally-disallow-P2P</link>	
		<description>Is there any &lt;b&gt;easy&lt;/b&gt; way to universally disallow P2P traffic on an office lan? &lt;br /&gt;&lt;br /&gt; Part of my job involves administering the office LAN.  I want to make sure that nobody on the network can run any sort of P2P.  This includes &quot;secure&quot; P2P such as &lt;a href=&quot;http://www.hamachi.cc/&quot;&gt;Hamachi.&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
When I say an &lt;b&gt;easy&lt;/b&gt; way, I mean &lt;b&gt;easy&lt;/b&gt;.  If there&apos;s a program that I can install, that would be great.  I would rather not delve into server internals or router/firewall configurations.&lt;br&gt;
&lt;br&gt;
If there is no easy way to block P2P traffic, I would be just as happy with a tool that could &lt;em&gt;diagnose&lt;/em&gt; P2P traffic.&lt;br&gt;
&lt;br&gt;
Network information -&lt;br&gt;
Windows and Mac OSX boxes&lt;br&gt;
Servers are Win2K&lt;br&gt;
Using a Tasman router and Pix 501 firewall</description>
		<guid isPermaLink="false">post:ask.metafilter.com,2006:site.30338</guid>
		<pubDate>Fri, 06 Jan 2006 13:11:56 -0800</pubDate>
		<dc:creator>Afroblanco</dc:creator>
		
			<category>network</category>
		
			<category>administration</category>
		
			<category>router</category>
		
			<category>firewall</category>
		
			<category>p2p</category>
		
			<category>peer</category>
		
			<category>to</category>
		
			<category>block</category>
		
	</item> <item>
		<title>By: hattifattener</title>
		<link>http://ask.metafilter.com/30338/How-to-universally-disallow-P2P#477269</link>	
		<description>Can you even &lt;i&gt;define&lt;/i&gt; P2P traffic in a concrete way?&lt;br&gt;
&lt;br&gt;
My guess is that the best you could do is set up firewall rules to block known protocols that you disapprove of, and keep updating that list as the set of popular protocols changes.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.30338-477269</guid>
		<pubDate>Fri, 06 Jan 2006 13:20:19 -0800</pubDate>
		<dc:creator>hattifattener</dc:creator>
	</item><item>
		<title>By: shepd</title>
		<link>http://ask.metafilter.com/30338/How-to-universally-disallow-P2P#477278</link>	
		<description>Well, the &quot;easy&quot; way would be to install a proxy server and disallow all internet access that doesn&apos;t go through it.  Then you can use the proxy server&apos;s configs to adjust it to only allow certain accepted traffic through it.  With a *LOT* of effort, someone might be able to tunnel through the thing, or get it to support some kind of P2P, but that level of user knows that what they&apos;re doing is wrong, and should be fired.  :-)&lt;br&gt;
&lt;br&gt;
Of course, this will be extremely limiting to what applications will support internet access (because they have to have proxy server support), so it might not be an option.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.30338-477278</guid>
		<pubDate>Fri, 06 Jan 2006 13:25:05 -0800</pubDate>
		<dc:creator>shepd</dc:creator>
	</item><item>
		<title>By: k8t</title>
		<link>http://ask.metafilter.com/30338/How-to-universally-disallow-P2P#477292</link>	
		<description>At my old office, we had a packet shaper (packeteer?) that allowed blocking of apps -- and you could click &quot;all p2p traffic.&quot;&lt;br&gt;
&lt;br&gt;
We set videoconferencing as the number 1 priority, then email, then http, etc. etc.&lt;br&gt;
&lt;br&gt;
As soon as it was turned on, people were angry!&lt;br&gt;
&lt;br&gt;
But I&apos;d say, &quot;So the head of HR is trying to have a videoconference and it is all fuzzy and choppy because you want to stream porn?&quot;</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.30338-477292</guid>
		<pubDate>Fri, 06 Jan 2006 13:30:20 -0800</pubDate>
		<dc:creator>k8t</dc:creator>
	</item><item>
		<title>By: klangklangston</title>
		<link>http://ask.metafilter.com/30338/How-to-universally-disallow-P2P#477323</link>	
		<description>Afroblanco: I always thought that the easy way WAS to mess with router settings. I&apos;ve had a couple of Linksys routers that I installed where the default was to block p2p traffic by way of IP masking. I had to disable that in order to use p2p and torrents.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.30338-477323</guid>
		<pubDate>Fri, 06 Jan 2006 13:43:10 -0800</pubDate>
		<dc:creator>klangklangston</dc:creator>
	</item><item>
		<title>By: nkyad</title>
		<link>http://ask.metafilter.com/30338/How-to-universally-disallow-P2P#477381</link>	
		<description>Maybe you can setup the users permissions so that they can&apos;t install anything. That would be easier but if there too many users and not enough support personnel you end up with a mutiny.&lt;br&gt;
&lt;br&gt;
But I agree the best and easiest way to do something about it is configuring the firewall/router to allow only some kinds of traffic. You see, if your job &lt;em&gt;&quot;involves administering the office LAN&quot;&lt;/em&gt; you will eventually have to &lt;em&gt;&quot;delve into server internals or router/firewall configurations&quot;&lt;/em&gt;. The sooner the better.&lt;br&gt;
&lt;br&gt;
And just a reminder: P2P, specially torrents, are becoming more and more common as a distribution channel for legitimate applications. In the end, this problem will have to be solved at another level (human resources and office rules) because the technology will be needed. The same way people know they can&apos;t go visiting porn sites at work, they will know they can&apos;t go downloading porn or music at work.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.30338-477381</guid>
		<pubDate>Fri, 06 Jan 2006 14:05:23 -0800</pubDate>
		<dc:creator>nkyad</dc:creator>
	</item><item>
		<title>By: voidcontext</title>
		<link>http://ask.metafilter.com/30338/How-to-universally-disallow-P2P#477385</link>	
		<description>Are you set up as a domain or as a workgroup?</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.30338-477385</guid>
		<pubDate>Fri, 06 Jan 2006 14:07:20 -0800</pubDate>
		<dc:creator>voidcontext</dc:creator>
	</item><item>
		<title>By: poppo</title>
		<link>http://ask.metafilter.com/30338/How-to-universally-disallow-P2P#477451</link>	
		<description>I&apos;m with nykad, just clean their PCs up and don&apos;t let them install anything.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.30338-477451</guid>
		<pubDate>Fri, 06 Jan 2006 14:57:37 -0800</pubDate>
		<dc:creator>poppo</dc:creator>
	</item><item>
		<title>By: Afroblanco</title>
		<link>http://ask.metafilter.com/30338/How-to-universally-disallow-P2P#477473</link>	
		<description>Thank you all for your suggestions thus far.&lt;br&gt;
&lt;br&gt;
voidcontext - we are set up as a domain&lt;br&gt;
&lt;br&gt;
nkyad - &lt;em&gt;You see, if your job &quot;involves administering the office LAN&quot; you will eventually have to &quot;delve into server internals or router/firewall configurations&quot;. &lt;/em&gt;&lt;br&gt;
&lt;br&gt;
LAN administration is really only a small part of my job.  Blocking P2P traffic isn&apos;t an urgent matter, but it&apos;s something that I would like to do if there is a quick and easy solution.&lt;br&gt;
&lt;br&gt;
&lt;em&gt;In the end, this problem will have to be solved at another level (human resources and office rules) because the technology will be needed.&lt;/em&gt;&lt;br&gt;
&lt;br&gt;
Good point.  This is another reason why it would be just as good if I could &lt;em&gt;diagnose&lt;/em&gt; P2P traffic.  I could keep the diagnostic tool running, and check the logs every so often, approaching users on a case-by-case basis.&lt;br&gt;
&lt;br&gt;
Does anybody know of such a tool?</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.30338-477473</guid>
		<pubDate>Fri, 06 Jan 2006 15:15:04 -0800</pubDate>
		<dc:creator>Afroblanco</dc:creator>
	</item><item>
		<title>By: formless</title>
		<link>http://ask.metafilter.com/30338/How-to-universally-disallow-P2P#477543</link>	
		<description>If you&apos;re looking to detect P2P traffic, or any other naughty traffic, one method is with an Intrusion Detection System.  &lt;a href=&quot;http://www.snort.org/&quot;&gt;Snort&lt;/a&gt; is a popular one.  But it&apos;s going to involve setup and administration.  And you&apos;ll need to determine what rules to enable and really what you want your companies network security policy to be.&lt;br&gt;
&lt;br&gt;
Even though they&apos;re called &lt;b&gt;intrusion&lt;/b&gt; detection systems, most of them will also detect anomalous outgoing traffic.&lt;br&gt;
&lt;br&gt;
But this wouldn&apos;t really be an &lt;b&gt;easy&lt;/b&gt; solution.  If you&apos;re looking for an easy solution, hire somebody to come in and clamp down your firewall and maybe outsource intrusion detection.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.30338-477543</guid>
		<pubDate>Fri, 06 Jan 2006 16:23:51 -0800</pubDate>
		<dc:creator>formless</dc:creator>
	</item><item>
		<title>By: nickerbocker</title>
		<link>http://ask.metafilter.com/30338/How-to-universally-disallow-P2P#477618</link>	
		<description>I&apos;m not really sure how to offer a better answer then what anyone else has already offered.  I do, however, have some advice.&lt;br&gt;
&lt;br&gt;
Be open and honest with your users from the get go about the whole thing.  I was surprised how many of my users really had a false since of privacy when it came to their work computers.  They need to know that since you are the administrator, everything they do and store on their work computers is accessible to you.  That sort of privilege (and responsibility) is part of the job title.&lt;br&gt;
&lt;br&gt;
Also make it clear that you aren&apos;t going to waist your time playing big-brother to your fellow employees, but something like a P2P application is going to stir your interest.  As well as burning company hours all day on some &lt;a href=&quot;http://www.metafilter.com&quot;&gt;web site&lt;/a&gt;.&lt;br&gt;
&lt;br&gt;
That way if you do have to come down on a user they don&apos;t get upset when they &quot;feel like their privacy has been invaded.&quot;&lt;br&gt;
&lt;br&gt;
Speaking from personal experience here.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.30338-477618</guid>
		<pubDate>Fri, 06 Jan 2006 17:33:47 -0800</pubDate>
		<dc:creator>nickerbocker</dc:creator>
	</item><item>
		<title>By: nkyad</title>
		<link>http://ask.metafilter.com/30338/How-to-universally-disallow-P2P#477636</link>	
		<description>&lt;b&gt;nickerbocker&lt;/b&gt; &lt;a href=&apos;http://ask.metafilter.com/mefi/30338#477618&apos;&gt;:&lt;/a&gt;  &lt;em&gt;&quot;As well as burning company hours all day on some &lt;a href=&quot;http://www.metafilter.com&quot;&gt;web site&lt;/a&gt;.&quot;&lt;/em&gt;&lt;br&gt;
&lt;br&gt;
With the added benefit of scaring your fellow workers away from the said web site, so you can keep burning your company hours here. There you are, your bonus answer, &lt;a href=&quot;http://www.theregister.co.uk/odds/bofh/&quot;&gt;BOFH 101&lt;/a&gt;.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.30338-477636</guid>
		<pubDate>Fri, 06 Jan 2006 18:10:17 -0800</pubDate>
		<dc:creator>nkyad</dc:creator>
	</item><item>
		<title>By: RikiTikiTavi</title>
		<link>http://ask.metafilter.com/30338/How-to-universally-disallow-P2P#477712</link>	
		<description>I second the &lt;a href=&quot;http://packeteer.com/&quot;&gt;PacketShaper&lt;/a&gt;.  It&apos;s designed for that, and does an excellent job of distinguishing P2P from other stuff.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.30338-477712</guid>
		<pubDate>Fri, 06 Jan 2006 21:15:08 -0800</pubDate>
		<dc:creator>RikiTikiTavi</dc:creator>
	</item><item>
		<title>By: ph00dz</title>
		<link>http://ask.metafilter.com/30338/How-to-universally-disallow-P2P#477839</link>	
		<description>If you&apos;re looking for something free, &lt;a href=&quot;http://www.ethereal.com/&quot;&gt;ethereal&lt;/a&gt; will do a pretty good job of showing all the activity on your network. I bet it&apos;d run great &lt;a href=&quot;http://ethereal.darwinports.com/&quot;&gt;under OS X&lt;/a&gt;.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.30338-477839</guid>
		<pubDate>Sat, 07 Jan 2006 07:14:06 -0800</pubDate>
		<dc:creator>ph00dz</dc:creator>
	</item><item>
		<title>By: caution live frogs</title>
		<link>http://ask.metafilter.com/30338/How-to-universally-disallow-P2P#477980</link>	
		<description>I think that a candid approach to the emplyees is the first step here. Knowing how frustrating it is to have to clean up a badly infected system - and also knowing as an end user how frustrating it is to be locked out of making changes to the computer I use daily - I think that personal intervention can go a long way as a first step.&lt;br&gt;
&lt;br&gt;
If you simply lock down all the machines people will find a way around it (sure I can&apos;t install this program locally, but I can run it off of my thumb drive...). If you leave the machines open and set up complicated filtering rules you&apos;re going to piss off people who have some favorite program or other blocked at the level of the server. If you explaion what the issue is first, and then set up a combination of the two (milder lockdown, less restrictive filter rules) you might be able to find a happy medium. Plus, you have a documented session in which yoiu have explained to everyone what is and is not acceptable use of the network. Makes it easier to reprimand abusers if necessary.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.30338-477980</guid>
		<pubDate>Sat, 07 Jan 2006 11:02:13 -0800</pubDate>
		<dc:creator>caution live frogs</dc:creator>
	</item><item>
		<title>By: vanoakenfold</title>
		<link>http://ask.metafilter.com/30338/How-to-universally-disallow-P2P#478029</link>	
		<description>Isn&apos;t the concept of a LAN and P2P transactions pretty much the same thing?  Easiest way (you didn&apos;t say smartest) would be to disconnect the LAN altogether or fire everyone ;-P</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.30338-478029</guid>
		<pubDate>Sat, 07 Jan 2006 12:21:36 -0800</pubDate>
		<dc:creator>vanoakenfold</dc:creator>
	</item><item>
		<title>By: Afroblanco</title>
		<link>http://ask.metafilter.com/30338/How-to-universally-disallow-P2P#478354</link>	
		<description>Thanks for the help, guys.  I&apos;m going to have to look into ethereal.  Packeteer looks good, but it seems like somewhat of a heavy-duty solution for my purposes.&lt;br&gt;
&lt;br&gt;
PS - thanks for the BOFH links, nkyad!  They made me laugh.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2006:site.30338-478354</guid>
		<pubDate>Sat, 07 Jan 2006 20:42:34 -0800</pubDate>
		<dc:creator>Afroblanco</dc:creator>
	</item>
	</channel>
</rss>
