Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kitty
New Contributor

How to block Hotspot Shield VPN

Hi all,

We are using the Fortigate 800C and I want to block traffic the Hotspot Shield VPN, is there anyone else who can help me?

 

Thanks a lot.

 

5 REPLIES 5
hmtay_FTNT
Staff
Staff

Hi kitty,

 

Please use the Application Control signature "Hotspot.Shield" to block the VPN. You will need to set the following signatures to Block too: "ISAKMP", "PPTP" and "L2TP". They are used on the iOS app to connect to the servers. Hotspot Shield VPN is one of the most evasive VPN, be sure to update your IPS Definition whenever a new one is available.

 

HoMing

kitty

Hi HoMing,If I block the two signatures: PPTP and L2PT anh then the VPN site to site is also be blocked?    Thanks for your support
hmtay_FTNT

Yes, if the outgoing PPTP and L2TP connection for your VPN site to site comes from the same firewall policy with those signature set to block, they will be blocked. 

 

There are ways you can get around this - like creating groups to specify which addresses gets exempted from the signatures. 

kitty

I am very grateful to you, when you replied the first posts I had a fresh idea to solve this case.

 

Thank you so much. See you soon 

 

 

 

hmtay_FTNT

You are welcome. Please let us know if you run into any issues. You can get to us here or PM me or open a support ticket with the TAC.

 

HoMing

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors