Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
buntha_na
New Contributor

FreeGate VPN

Dear Everyone!!!!

I use Fortigate 300c 5.0 i am already block app Freegate but this application still access proxy by pass out of our firewall.

Please see picture:

5 REPLIES 5
kobby
New Contributor

I am facing this challenge as well.  Any help?

 

buntha_na

Hi Kobby!

Can you add these 2 custom application control signatures?

F-SBID( --name "Freegate.Cloudfront.Custom"; --protocol tcp; --flow from_client; --service SSL; --seq =,1,relative; --data_size =114; --pattern "|16 03 01 00 6d 01 00 00 69 03 01|"; --context packet; --within 11,context; --pattern "|ff 01 00 01 00|"; --context packet; --distance 5,context,reverse; --within 5,context; --pattern ".cloudfront.net"; --context host; --no_case; --app_cat 6; )

F-SBID( --name "Freegate.Custom"; --protocol tcp; --flow from_client; --service SSL; --seq =,1,relative; --data_size =77; --pattern "|16 03 01 00 48 01 00 00 44 03 01|"; --context packet; --within 11,context; --pattern "|00 00 16 00 04 00 05 00 0a 00 09 00 64 00 62 00 03 00 06 00 13 00 12 00 63 01 00 00 05 ff 01 00 01 00|"; --context packet; --distance 32; --within 34; --app_cat 6;)

The action Block it's the way to block Freegate fine, I am already apply it in my environment it's working as well.

Best Regard,
Yin Buntha
kobby

I've done that but not working.

Fullmoon
Contributor III

see to it that SSL/SSH Inspection profile under Policy & Object applied correctly to specific policy.

Fortigate Newbie

Fortigate Newbie
reedone816
New Contributor

yes this happened to me too, I already using Application control, but only succeed in blocking A type connection, but the F type is only blocked once, then the next one can go through.

I already give up on this freegate, right now i only use firefighting technique, go after the person that using one, spied from fortiview...

Labels
Top Kudoed Authors