L7 P2P Blocking Limewire Ver 4.18.3 & Tom 1.19 - 1.21

Discussion in 'Tomato Firmware' started by DJB31st, Aug 6, 2008.

  1. DJB31st

    DJB31st Addicted to LI Member

    It appears that the latest version of Limewire can bypass the L7 access restrictions of the Tomato Firmware.

    We have noted that the restriction used to work on our network and returning to an older version of Limewire confirms the issue as this is blocked.

    To replicate the issue,

    Using Tomato v. 1.21

    Setup the restrictions as

    TCP/UDP, IPP2P: All IPP2P Filters

    Install Limewire 4.18.3 (http://www.limewire.com/)

    Try to download a file. (this is successful)

    Additionally we have noticed that "limewire" does not show up in the program list for L7 restrictions, as it is a popular P2P software, we would expect this?

    If anyone wants a copy of the NVRAM variables, then i will send them over.


  2. azeari

    azeari LI Guru Member

    1 thing to note is L7 restrictions are not 100% effective, as they attempt to identify packets based on known-behavioral patterns only.

    also, L7 rules don't apply to access restrictions, only QOS, thus limewire working should be an expected behavior.

    well lastly, the L7 rules aren't maintained by the author of this software (= so tts outta his league.

    hope i cleared up a lil stuff (=

    edit: my suggestion, wait for the next version and hope the updated rules fixes the new L7 loophole
