> Source: [sk110018](https://support.checkpoint.com/results/sk/sk110018)

# sk110018 - Torrent traffic bypasses application rules and is allowed

| Property | Value |
|----------|-------|
| Solution ID | sk110018 |
| Date Created | 2016-02-18 |
| Last Modified | 2016-03-06 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- SmartView Tracker shows that BitTorrent traffic has been blocked, although in fact new torrents are able to be started from within the network and paused torrents are able to be successfully resumed.  

The below snapshot shows the application rulebase blocked the torrent when it was allowed:  

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk110018/sk110018_Torrents_blocked.png)

## Cause

BitTorrent is a peer-to-peer protocol. A cluster or group of computers uploading/downloading the same torrent are said to be in a "swarm".

**Potential reasons why torrents may be able to bypass the application control rules:**

1. Improper rules placement can cause the torrents to bypass Application rules check and get full access to uploading or downloading
2. Rule ordering
3. An open allow all rule instead of a cleanup rule
4. Application Control signatures are not updated

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
