Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

p2p blocking on Cisco IOS

Hi,

Is there any way to block any p2p traffic but not based on TCP/UDP ports but the content or certain pattern of the p2p packets on Cisco router?

I know use of NBAR but there can't be found all p2p protocols.

Thanks for any suggestions.

Remi

5 REPLIES

Re: p2p blocking on Cisco IOS

Remi,

If NBAR is not catching the particular application, you can download and enable extra specific PDLM files - these are add on's to the existing NBAR classifications in the router IOS.

HTH>

Community Member

Re: p2p blocking on Cisco IOS

Hi,

Thanks for your suggestions. I did take a look for the latest PDLMs and could not find any for ARES, LIMEWIRE or Bittorrent.

I am not sure if there are any PDLMs covering those applications. ARES is very nasty, uses dynamicly assigned ports from unspecified range.

I looked into ZPF config guides and it looks like with latest IOSs, Cisco added p2p applications for inspect so that with policy-map it could be policed to drop certain traffic maching certaing applications. Those features are available on 880 series for instance but I am working with 870 series.

Maybe you know of any PDLMs that would support ARES or LIMEWIRE.

Thanks a lot in advance.

Remi

Community Member

Re: p2p blocking on Cisco IOS

The application firewall feature of CBAC can block p2p traffic based on the content of the packet and not the port it is using.

Please look under HTTP, POP/IMAP, and SMTP/ESMTP Application Inspection

http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5708/ps5710/ps1018/product_implementation_design_guide09186a00800fd670.html

Community Member

Re: p2p blocking on Cisco IOS

Hi,

Many thanks for additional clues but I guess ARES is not supported.

Community Member

Re: p2p blocking on Cisco IOS

Please rate if it was useful.

Thx

711
Views
4
Helpful
5
Replies
CreatePlease to create content