    I'm having a problem with l7:http almost never matching an HTTP connection. It only seems to match about 30% or so of actual HTTP connections. Any tips or hints on why that might be? l7:ssl works perfectly.

    I was using just port 80 and port 443 but I noticed Bittorrent clients using those ports to cruise through the speed restrictions.
    Yes, many of the L7 filters are pretty useless. And it's very hard to do much about bit torrent using some popular ports, but usually one can tolerate some bleed-through without too much trouble, if your bandwidth is reasonably high.
    Thanks. I suppose a judicious combination of limiting simultaneous connections and slowing down HTTP after X bytes should be of assistance here.
