News: This forum is now permanently frozen.
Pages: [1]
Topic: L7-Filter needed  (Read 4967 times)
« on: February 21, 2009, 16:19:09 »
bofh *
Posts: 3

Hello,

If M0n0wall would include the L7-Filter, so that you could control or prevent traffic (especially P2P traffic) based on the protocol and not only based on the port it uses, then it would be really perfect!

M0n0wall is a really a great firewall solution, but the ability to prevent especially P2P traffic is (IMHO) even more important as other advanced firewall features like VPN, traffic shaping, high availability etc. which are already built-in.
Therefore I am surprised to find the L7-filter (or comparable) is not even on the wishlist.

I'd love to contribute this to the project, but unfortunately I don't have the skills.
But if a small donation is all it takes, then let me know.

Thank you and best Regards

Peter
« Reply #1 on: February 21, 2009, 19:44:04 »
knightmb ****
Posts: 341

Something like this?

http://www.untangle.com/m0n0wall?cmpid=ad-ban-m0n0

Radius Service for m0n0wall Captive Portal - http://amaranthinetech.com
« Reply #2 on: February 21, 2009, 21:42:51 »
bofh *
Posts: 3

Hi,

Sure you can run Untangle or another separate solution in addition to M0n0wall, but that's what I'd like to avoid.

At the moment I run an older version of fli4l (http://www.fli4l.de) with the IPP2P module (http://www.ipp2p.org) just for the purpose of filtering P2P in addition to M0n0wall on a separate ALIX. But the IPP2P filter is not maintained any more.

Untangle doesn't even run on ALIX. When using Untangle I'd have to run an additional PC just to ensure that nobody can do P2P on my DSL (and I don't get trouble because of their downloads!).

Therefore it would be great if the L7-filter could be included in M0n0wall.

Regards

Peter
« Reply #3 on: February 22, 2009, 07:06:07 »
knightmb ****
Posts: 341

Hi,

Sure you can run Untangle or another separate solution in addition to M0n0wall, but that's what I'd like to avoid.

At the moment I run an older version of fli4l (http://www.fli4l.de) with the IPP2P module (http://www.ipp2p.org) just for the purpose of filtering P2P in addition to M0n0wall on a separate ALIX. But the IPP2P filter is not maintained any more.

Untangle doesn't even run on ALIX. When using Untangle I'd have to run an additional PC just to ensure that nobody can do P2P on my DSL (and I don't get trouble because of their downloads!).

Therefore it would be great if the L7-filter could be included in M0n0wall.

Regards

Peter

Being that Untangle is it's own project, I'm guessing that such an addition to m0n0wall would be very large, in that m0n0wall can already run fast on very low end hardware (by today's standard of low end anyway) and that software similar to Untangle or others was probably a much larger task than the devs would like to tackle at the moment. I'm sure if someone had the time and resources, maybe they could port some code over from Untangle or others, but if you look at the specs on a filter, they would push m0n0wall way out of the league of most of the hardware we run here. I wouldn't mind having a cool feature like Untangle in m0n0wall, but then I would also need to upgrade to a lot more RAM and CPU speed, HDD space just for the feature. If it was something you could turn off, then yeah, m0n0wall could still run like it always did, but the new feature would eat up a ton of HDD space just to keep it around. It would probably require two builds, one with and without the feature for all the hardware types. Actually just talking about it, I realize this would actually take a lot of work and effort to get started, so yeah, I think that's why m0n0wall has an Untangle link right on the front page, for that very reason at the moment.  Smiley

Radius Service for m0n0wall Captive Portal - http://amaranthinetech.com
« Reply #4 on: February 22, 2009, 12:47:58 »
bofh *
Posts: 3

Forget about Untangle here!

Sorry that I have not given the most important link here so far: http://l7-filter.sourceforge.net/
It is a module for netfilter. I assumed that this project is known.

Concerning the hardware resources I'd like to add, that we currently run a comparable filter (http://www.ipp2p.org - works but it is not maintained any more) on FLI4L (http://www.fli4l.de) on WRAP! In combination with the module for connection tracking it is no problem as only the first packet of a connection has to be classified then. Therefore I am quite sure that an ALIX should surely have sufficient CPU to filter a typical DSL connection.

Again I'd like to point out that the L7-filter would not mean more complexity and hardware resources then e.g. IPSEC, which is already integrated in M0n0wall. Only that the L7-filter is much more important in a firewall distribution then an VPN gateway (IMHO).

Regards

Peter
« Reply #5 on: February 23, 2009, 00:17:00 »
Manuel Kasper
Administrator
*****
Posts: 364

m0n0wall does not use iptables/netfilter or Linux - instead, it's based on FreeBSD and ipfilter. Therefore, we won't be able to use L7-filter. I'm not aware of something similar for FreeBSD at this time...
« Reply #6 on: April 04, 2009, 04:21:24 »
tekkon *
Posts: 1

Is m0n0wall based on ipfw or ipfilter? I looked here - http://m0n0.ch/wall/facts.php - seems to be running ipfilter.

I just wanted to point out that there has been development for an application layer classifier for ipfw - http://lists.freebsd.org/pipermail/freebsd-net/2008-July/019086.html - named ipfw-classifyd.

The pfSense project will be implementing ipfw-classifyd with pf in their upcoming 2.0 release. - http://roadtoqos.wordpress.com/
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines