Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

DRUMDUDESAN
New Contributor

How to block other VPN software from the Enterprise

Hi,
I just went through an investigation of chasing down MAC address spoofing in our environment. In summary a client installed Avast VPN on their endpoint. It kept randomly changing the mac address of it's endpoint. We are a development shop so they all have admin/root access to their endpoints.
How I can block VPN software like Avast on the FortiGate firewall? Their must be a list of their Avast VPN IP addresses listed somewhere but I cannot find it as that is what I was thinking of doing although that could change.
I was thinking of a more global approach but I am unsure what to do.
- FortiGate 500D
Thanks
Jeff

------------------------------
Jeff Gover [Designation]
IT Team Lead
[CompanyName]
[City] [State]
[Phone]
------------------------------
2 REPLIES 2
jvales
New Contributor

Hello,

Not easy.

You can block standard VPN ports for  PPTP, IPSEC, L2TP
But if your user use the version PRO, the VPN can be configured to use SSL.
If you block  DNS names with words liek avast or VPN , there is an option in Avast Secure Line (VPN) to use IP addresses.

regards
José

------------------------------
José

------------------------------
rmoussa
Contributor

Hi,

In your case, maybe you can consider creating a custom signature for that application and block it.

Regards
Rony

------------------------------
Rony Moussa
Fortinet NSE Certified: Level 8
------------------------------
Rony Moussa
Fortinet NSE Certified: Level 8
Rony MoussaFortinet NSE Certified: Level 8
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.