FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
vpereira
Staff
Staff

Description
This article describes how to block TOR traffic from the WAN to the LAN, by using the ISDB object.
This ISDB object contains a list of all TOR exit nodes currently known and is updated by FortiGuard.

 

Scope

Fortigate


Solution
Go to Policy & Objects -> IPV4 Policy and select 'Create New'.
Incoming interface: WAN.
Outgoing interface: LAN.

Go to Source -> Internet Service, search for 'Tor' and select 'Tor-Exit node'.

When creating the policy is finished, place it as high in the policy list.
Since policy lookup is done from top to bottom, place this policy as high as possible to prevent traffic coming from TOR to run through all the other policies above it.


Application Control can be used as well:

 

Blocking Tor traffic using the Application Control profile

  1. Go to Security Profiles -> Application Control and edit the App control profile.
  2. Under Application Overrides, select Add Signatures.
  3. Search for Tor, then filter the results to show only the Proxy category.  Two signatures will appear one for the Tor client, one for web-based Tor2web & TorGuard.
  4. Highlight both signatures, and select Use Selected Signatures.
  5. Both signatures now appear in the Application Overrides list, with the Action set to Block.

2022-03-30 17_00_14-FortiGate - tachyon-kvm13 — Mozilla Firefox.png