Firewall Wizards mailing list archives

Re: QoS and P2P?


From: Mikael Olsson <mikael.olsson () clavister com>
Date: Tue, 05 Nov 2002 18:23:38 +0100


Paul Robertson wrote:

What's interesting to me about [NBAR] is how the ISPs who are blocking 
P2P software such as Kazaa, Gnutella, Morpheus, Grokster, iMesh
and Napster may be using this.

In my opinion, trying to do filtering per application in a public 
network is a complete waste of time.  In any given public network, 
you'll have a very low percentage of users using up almost all the 
available bandwidth.

Those users are also very tech savvy, compared to the general populus.

If they realize you are applying bandwidth limits to one port, they'll
move to another port. If they realize you are applying bandwidth 
limits to one PoP application, they'll move to another PoP application.

If they realize you are applying bandwidth limits to ALL PoP 
applications, well, hey, there's always HTTP and FTP, and there are 
friends all over the Internet. And places like "iDrive" (on-line
storage via HTTPS).


To me, the only solution is to set up a "bandwidth balancer" that 
portions out the available bandwidth in a fair way. This way, it
doesn't matter what they're running. If they're l33ch1ng too hard,
well, _their_ downloads are likely the ones to be limited the most
by the per-user bandwidth limits as they start decreasing in 
response to overload.

Added bonus: when the load on the network as a whole is lower, their
transfers will finish faster, and hopefully be done by the time the
total load rises again.


I'm involved from time to time in the infrastructure of a fairly 
large public access network, and also a user of said network at 
home.  We use plain bandwidth balancing and I'll have to say that 
it works very well.

-- 
Mikael Olsson, Clavister AB
Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden
Phone: +46 (0)660 29 92 00   Mobile: +46 (0)70 26 222 05
Fax: +46 (0)660 122 50       WWW: http://www.clavister.com
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: