Block QUIC - Tighten down your Internet traffic futher.

Поділитися
Вставка
  • Опубліковано 21 жов 2024

КОМЕНТАРІ • 19

  • @blindside995
    @blindside995 Рік тому +2

    Great Video Willie! Really been enjoying the firewall lockdown series.

  • @SickBeard
    @SickBeard Рік тому +4

    Minor nitpick, but talking about the current iteration of QUIC like it was developed by Google is like saying SSL/TLS was developed by Netscape.
    Technically true, but vastly different now than X years ago.

  • @DeliberateGeek
    @DeliberateGeek Рік тому +1

    As always, great video. I'll have to do a bit more research on this to determine the best settings for me. I'm using a UDMP for a home network. I disabled QUIC and a day or two later, discovered that the Instagram app fails without it, so the family had a fit. Gotta decide whether to block it for specific networks, or block it for all networks, but allow it from certain sources, etc...

  • @martincourtemanche2724
    @martincourtemanche2724 Рік тому +1

    Would you know why one would have to use the Traffic Management if a Firewall rule is already in place? I used the Traffic Management rules and the traffic was still passing through, but changed it to the Firewall rules and only then did the traffic stopped passing.

  • @Red1Wollip
    @Red1Wollip Рік тому

    Willie you are the best my friend!

  • @mehrdadfeller
    @mehrdadfeller 3 місяці тому

    You are not blocking QUIC specifically, you are blocking all UDP traffic on port 80 & 443 which is broader than QUICK itself. What if some other service wants to send UDP packets on those ports?

  • @jackkopp7155
    @jackkopp7155 Рік тому +6

    Typo - you blocked UDP 433 instead of 443.

  • @Jianju69
    @Jianju69 5 місяців тому +2

    "...good for voice and video," (also awesome for games, btw) "-but that's all you can do with it so just block it."
    Because nobody wants to do voice, video, or games?

  • @jasonluong3862
    @jasonluong3862 Рік тому

    Can the firewall be configured to allow QUIC for specific hosts in the LAN or specific VLAN? Blocking QUIC for the entire LAN is overkill. For example, how about allowing QUIC for IoT devices like smart TVs. These devices use a lot of data so QUIC would reduce processing load, but given the data is just videos, security is not important, especially when they are assigned their own VLAN.

    • @blindside995
      @blindside995 Рік тому

      You definitely can. The way I would do that. Is make an IP Group that you do not want QUIC blocked on and put them in the destination. LAN-IN destination. I could be mistaken, but I think that is certainly a way you could do it.
      Alternately, make an allow rule above that one for those specific network with the protocol QUIC.

  • @JohnSmith-sc6jt
    @JohnSmith-sc6jt Рік тому

    My Unifi network app. Shows a different Traffic Management screen. It doesn't have rules that gives a list like what is shown. It has a place to create static routes and then a place for traffic restrictions. It requres a Add Restriction Group and the dropdown list for categories gives general options like "Business Tools", "File sharing services and tools", and others, but no list to block specific web sites, domains or apps. I thought I was in the latest version of 7.3.83, at least when I check updates it tells me I have the latest. Any tips?

    • @Jr2728
      @Jr2728 Рік тому

      Which unifi control do you have?

    • @JohnSmith-sc6jt
      @JohnSmith-sc6jt Рік тому

      @@Jr2728 I am using the application version 7.3.83 with a USG

  • @kristopherleslie8343
    @kristopherleslie8343 Рік тому

  • @jamiebarnes3539
    @jamiebarnes3539 Рік тому

    most services use QUIC blocking it will cause you problems.

    • @martincourtemanche2724
      @martincourtemanche2724 Рік тому +1

      I'm looking into this, but I can't find one that didn't one that did not cause me problems and my network are complex. Would you be able to share with us one typical service that is affected by such a rule? thx

  • @vonnikon
    @vonnikon 5 місяців тому

    Blocking QUIC makes the internet experience slower and more annoying for all your users.
    I hope they enjoy watching loading-screens...

    • @WillieHowe
      @WillieHowe  5 місяців тому

      If quic is blocked in can fail back to other means. However -- in corporate and school networks where you have to have control, blocking quic is the right thing to do.

    • @Jianju69
      @Jianju69 5 місяців тому

      @@WillieHowe Sure, but the video frames it more like [everyone should block QUIC because all it can do is voice and video.]