<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Block Peer-2-Peer Traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/block-peer-2-peer-traffic/m-p/1882797#M456775</link>
    <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got ASA 5510 with base license, can I block all Peer-2-Peer traffic from inside to outside. &lt;/P&gt;&lt;P&gt;ASA Giga 0/0 connected to ISP Router 2811&lt;/P&gt;&lt;P&gt;ASA Giga 0/1 connected to LAN switch 3560&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks upfront&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 22:56:44 GMT</pubDate>
    <dc:creator>joseph.steve</dc:creator>
    <dc:date>2019-03-11T22:56:44Z</dc:date>
    <item>
      <title>Block Peer-2-Peer Traffic</title>
      <link>https://community.cisco.com/t5/network-security/block-peer-2-peer-traffic/m-p/1882797#M456775</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got ASA 5510 with base license, can I block all Peer-2-Peer traffic from inside to outside. &lt;/P&gt;&lt;P&gt;ASA Giga 0/0 connected to ISP Router 2811&lt;/P&gt;&lt;P&gt;ASA Giga 0/1 connected to LAN switch 3560&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks upfront&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:56:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-peer-2-peer-traffic/m-p/1882797#M456775</guid>
      <dc:creator>joseph.steve</dc:creator>
      <dc:date>2019-03-11T22:56:44Z</dc:date>
    </item>
    <item>
      <title>Block Peer-2-Peer Traffic</title>
      <link>https://community.cisco.com/t5/network-security/block-peer-2-peer-traffic/m-p/1882798#M456778</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Steve, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In majority of cases you will not be able to block it completly, unless you go for full restriction of outgoing ports/protocols except the ones needed by your users and then you also need to check for integrity of those (HTTP inspection, proxy server for HTTP/HTTS request) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P2P are known to tunnel inside other protocols (HTTP and HTTPS are usually preferred) and mechanisms (toredo, 6to4, etc). Most use some level of encryption and even some IPSes are not able to cope with that - are are able to dectec only parts of traffic. Dynamic ports, upnp, megnet links, and a lot more. &lt;/P&gt;&lt;P&gt;And this is only for bittorrent. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Apr 2012 08:01:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-peer-2-peer-traffic/m-p/1882798#M456778</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2012-04-21T08:01:57Z</dc:date>
    </item>
    <item>
      <title>Block Peer-2-Peer Traffic</title>
      <link>https://community.cisco.com/t5/network-security/block-peer-2-peer-traffic/m-p/1882799#M456780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Any template from Cisco to block the minimum threats&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Apr 2012 09:40:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-peer-2-peer-traffic/m-p/1882799#M456780</guid>
      <dc:creator>joseph.steve</dc:creator>
      <dc:date>2012-04-21T09:40:38Z</dc:date>
    </item>
    <item>
      <title>Block Peer-2-Peer Traffic</title>
      <link>https://community.cisco.com/t5/network-security/block-peer-2-peer-traffic/m-p/1882800#M456782</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have a look here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808c38a6.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808c38a6.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But don't have too high hopes in this being the solution to all problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seconds thing to consider is threat-detection to a degree it can stop some of the activity by very chatty hosts (which p2p usually are). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have an IPS/IDS somehwere you can detect un-encrypted part of P2P and drop it - signaures exist. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IOS has nbar - it can detect quite a lot of common p2p and (via class map/policy-map) drop traffic - again don't have high hopes for this as solution to fix all the problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Apr 2012 08:49:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-peer-2-peer-traffic/m-p/1882800#M456782</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2012-04-22T08:49:13Z</dc:date>
    </item>
  </channel>
</rss>

