EFW Support

Support => General Support => Topic started by: arminf on Wednesday 03 March 2010, 06:22:51 am



Title: Bittorent Configuration -> bypass IDP
Post by: arminf on Wednesday 03 March 2010, 06:22:51 am
Hello Everyone

As i like to run bittorent my config for the endian 2.3 is the following

Outgoing firewall configuration
my server ip to RED any port/protocol
(no worry its a virtual machine ;-))

Incoming firewall configuration
Incoming routed traffic to my server ip port for bittorent

When i check the log i see a lot of IDS messages stating my server ip address.
checked the proxy settings which includes client ports from 1024 to 65k..
I guess this make the trouble. Downloads are running and connections are passing through but i really looks bad on the log with all those idp warnings..

snort[23669]: [1:2000334:9] ET P2P BitTorrent peer sync [Classification: Potential Corporate Privacy Violation] [Priority: 1]: {TCP} 192.168.1.100:45498 -> x.x.x.x:PORT

Do you run bittorent? Whats your setup?

Any suggestion would be highly appreaciated!
thanks!
regards armin