Re: [squid-users] URL/P2P blocking

2016-05-04 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Just for information: http://pastebin.com/dBYV9Zzb Here is completely actual Cisco NBAR filtering capabilities from one of my front 2901 with IOS 15.5 + actual NBAR2 protocol pack. Just take a look. You can see there P2P, Torrents, FB, YT, etc.e

Re: [squid-users] URL/P2P blocking

2016-05-04 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Finally, read this thread too: http://www.spinics.net/lists/squid/msg81113.html Some questions already answered here. 05.05.16 3:26, Yuri Voinov пишет: > > As a part of solution I recommend (by my own experience) consider to use this: > > https

Re: [squid-users] URL/P2P blocking

2016-05-04 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 As a part of solution I recommend (by my own experience) consider to use this: https://www.urlfilterdb.com/products/ufdbguard.html But I repeat: this is NOT magic button "Disable all". This is relatively effective tool to block categories. This

Re: [squid-users] URL/P2P blocking

2016-05-04 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Generally, for effective blocking of everything better design would first consider - as everyone and everything is engeneered, and then look for the magic button "to disable all to hell." Then it becomes clear what is possible and what means - and

Re: [squid-users] URL/P2P blocking

2016-05-04 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Facebook uses Akamai as background CDN, so you need to block Akamai (related URL's, which can be difficult, so consider to use Cisco NBAR DPI functionality). too in case to completely block FB. YT still uses QUIC/SPDY, so read this http://wiki.sq