We are currently working through blocking VPN's on our FortiGate 600D. It seems like we are spinning our wheels trying to chase down individual VPNs that our students are using to circumvent our security measures. How are you all handling the blocking of mobile device VPNs at a macro level? It doesn't seem feasible to chase down, block and test the hundreds of VPNs that are currently available.
Thanks for your input.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello zwilson50,
To block the VPNs, please set the category "Proxy" and the signatures "PPTP", "L2TP" and "ISAKMP" to Block. That should block most if not all the VPNs you can find.
As to how we try to cover all the VPNs, from our research, 80-90% of the common VPNs in the market use some forms of the OpenVPN protocol that our "OpenVPN" signature would block. For those that do not use the OpenVPN protocol, many share the same servers or API calls. This signature works for most of Android and Windows VPNs.
For iOS VPNs, because of strict restrictions by Apple that VPNs need to use PPTP, L2TP or IPSec (we name the signature ISAKMP), blocking those 3 signatures would block most of the VPNs on iOS.
The remaining VPNs that are not covered by the signatures above are covered by the other signatures in our Proxy category. We have our tools that monitor when these apps are updated and we update our signatures accordingly. We give special priority to certain very evasive VPNs like Ultrasurf, Psiphon, Hotspot Shield, Freegate, etc because they employ very complicated protocols to bypass firewalls.
HoMing
I have a similar problem, but I'm trying to block VPN clients that use SSL-TLS. What's the best way of doing this? We can't block SSL-TLS totally since it is used by browsers, etc.
How do we bypass this block, considering all VPN's have been blocked. Ultrasurf, Psiphon, Hotspot Shield, Freegate are also blocked with the help of a certificate installed in the device without which the wifi won't work. Can you please tell me if there is a way around all these blocks?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1640 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.