OUTBOUND FILTERING AND BIT TORRENT bitlord

OUTBOUND FILTERING AND BIT TORRENT bitlord

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
OUTBOUND FILTERING AND BIT TORRENT bitlord navti 05-16-2007
Posted by navti on May 16, 2007, 5:36 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I am using a bit torrent client called bit lord.

I set up outbound filtering on my firewall to only allow access to
ports 80 and 443 for web surfing,

Now , obviously , bit lord wont work.

Question :

which outbound ports do i need to open ?

since bitlord is connecting to peers which can have any port set as
the server port then it appears i have to allow outbound traffic to
all TCP Ports in order to allow bitlord to connect,

IS this correct ?


Posted by Sebastian G. on May 16, 2007, 8:54 am
If you were  Registered and logged in, you could reply and use other advanced thread options
navti wrote:

> I am using a bit torrent client called bit lord.
>
> I set up outbound filtering on my firewall to only allow access to
> ports 80 and 443 for web surfing,
>
> Now , obviously , bit lord wont work.
>
> Question :
>
> which outbound ports do i need to open ?


If you can't answer this question yourself (including RTFM and taking a look
at your log file), then you shouldn't try to run a firewall.

> since bitlord is connecting to peers which can have any port set as
> the server port then it appears i have to allow outbound traffic to
> all TCP Ports in order to allow bitlord to connect,
>
> IS this correct ?

No, it's pure nonsense, showing that you don't even understand what TCP
states and stateful filtering are. Please do yourself a favor and stop
thinking that you could run a firewall.

Posted by navti on May 16, 2007, 9:27 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> navti wrote:
> > I am using a bit torrent client called bit lord.
>
> > I set up outbound filtering on my firewall to only allow access to
> > ports 80 and 443 for web surfing,
>
> > Now , obviously , bit lord wont work.
>
> > Question :
>
> > which outbound ports do i need to open ?
>
> If you can't answer this question yourself (including RTFM and taking a look
> at your log file), then you shouldn't try to run a firewall.
>
> > since bitlord is connecting to peers which can have any port set as
> > the server port then it appears i have to allow outbound traffic to
> > all TCP Ports in order to allow bitlord to connect,
>
> > IS this correct ?
>
> No, it's pure nonsense, showing that you don't even understand what TCP
> states and stateful filtering are. Please do yourself a favor and stop
> thinking that you could run a firewall.

wow. thanks. I dont have a stateful firewall. I have a SOHO firewall.
A Netgear DG834G to be precise,

It allows basic packet filtering rules only.

So I have to open up outbound traffic to certain TCP ports.

Looking at the logs I can see that Bitlord is making outbound
connections to many many different TCP ports,

The only way I can get it to work is to allow all outbound TCP.

inbound traffic is not an issue as BitLord will work quite happily
with outbound connections only,



Posted by Sebastian G. on May 16, 2007, 9:55 am
If you were  Registered and logged in, you could reply and use other advanced thread options
navti wrote:


> wow. thanks. I dont have a stateful firewall. I have a SOHO firewall.
> A Netgear DG834G to be precise,


What's that supposed to mean? Almost any SOHO firewall should do stateful
filtering, and a Netgear DG834G clearly should.

> It allows basic packet filtering rules only.


This just means that you can't refer to the TCP states in your ruleset. A
bit limiting, but not relevant for your case.

> So I have to open up outbound traffic to certain TCP ports.


Ehm... yes. I wonder why you even limited outbound connections.

> inbound traffic is not an issue as BitLord will work quite happily
> with outbound connections only,

Doubtful. But again, this is a case of RTFM.

Posted by navti on May 16, 2007, 10:29 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> navti wrote:
> > wow. thanks. I dont have a stateful firewall. I have a SOHO firewall.
> > A Netgear DG834G to be precise,
>
> What's that supposed to mean? Almost any SOHO firewall should do stateful
> filtering, and a Netgear DG834G clearly should.
>
> > It allows basic packet filtering rules only.
>
> This just means that you can't refer to the TCP states in your ruleset. A
> bit limiting, but not relevant for your case.
>
> > So I have to open up outbound traffic to certain TCP ports.
>
> Ehm... yes. I wonder why you even limited outbound connections.
>
> > inbound traffic is not an issue as BitLord will work quite happily
> > with outbound connections only,
>
> Doubtful. But again, this is a case of RTFM.

inbound traffic is not an issue i can assure you.

it works fine with all inbound traffic denied,

my manual tells me it only needs outbound connections to work.

so i set up a basic filter to allow TCP outbound to ports 6000-7000

and i block everything else

i look in the logs and i look at my bitlord client

what do i see ?

i see that some outbound connections are working ie those to peers
listening on ports in the range 6000-7000

so i can get some traffic

i see that traffic to peers listening on other TCP ports are blocked

i increase thse scope of my filter to allow TCP 1000-65535 and i get
most traffic

some is still filtered to peerfs using TCP ports outside that range

so the only way i can see is to allow ALL TCP traffic outbound

have you actually tried this yourself ?


Similar ThreadsPosted
outbound filtering December 26, 2006, 12:52 pm
Microsoft TechNet Magazine Article about Outbound Filtering June 14, 2006, 6:07 pm
Configuring F-Secure Firewall Ports for Bit Torrent December 23, 2004, 7:13 am
Azureus port problem for Torrent with windows firewall March 12, 2006, 3:06 pm
Blocking Outbound Traffic Only July 23, 2004, 8:40 pm
Unexpected Outbound SSH traffic June 9, 2006, 4:37 pm
Vista FW outbound check July 15, 2007, 5:00 am
FortiGate FG60 and outbound NAT December 4, 2007, 9:13 am
Suggestions for a outbound firewall? July 10, 2008, 12:24 pm
SonicWall SOHO3 - allowing outbound ftp November 10, 2005, 8:46 am

The site map in XML format XML site map

Contact Us | Privacy Policy