4 ms·
Perhaps they were trying to block (encrypted) P2P downloads and gaming. In such case it would be a "good enough" solution, because it is hard to convenience eve
by nirui 5y ago
Perhaps they were trying to block (encrypted) P2P downloads and gaming. In such case it would be a "good enough" solution, because it is hard to convenience every each P2P peer or game server to use whitelisted ports.
Detecting protocol is hard, and much expensive than just port blocking. So I guess the admins were trying to do the best job possible with the limited equipment on their hands.
- jeroenhd 5y agoDetecting bittorrent isn't that hard, and neither is detecting most popular p2p traffic. It's CPU intensive though, requiring something like snort to run basic protocol heuristics on every packet. Just blocking as much outgoing udp as possible would be the poor man's solution to a network policy like that. There's also ways to cloak network traffic, of coarse. Of course, in practice, all of the bandwidth can still be sucked up by p2p through VPNs which are probably allowed through the network, so I'm not really sure what the problem those restrictions try to solve is.
- Macha 5y agoWe just ran our own servers on port 443 - We tried 80 at first but I guess they did have something rejecting non-http traffic on that port, while I guess for 443 they just assumed everything not understood was https. Also LoL worked whatever they did. Maybe that was just the admin's game of choice
- BiteCode_dev 5y agoI think my classmates in IT school learned much more from bypassing the network restrictions to play WoW in class than from the teachers themself.