Fortigate Newbie
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
Can you update your IPS Definition to 10.00071 or above. An update on the Psiphon signature was released in 10.00071 to cover the recent update.
On the same topic, with IPS Engine 3.00299 and FortiOS 5.4 and above, our Psiphon signature does not require SSL deep-inspection anymore. We have added a new feature into the engine that allows us to block it without deep inspecting the packet.
I have update IPS and FOS but still Psiphone can bybass the fortigate?? any help please
Did you enable certificate-inspection or deep-inspection? Can you show me the output to the CLI command "diagnose autoupdate versions? Can you send me your configuration file in a PM? Thanks.
HoMing
dear hmtay_FTNT,
TAC sent me IPS signature FOS 5.2.10 (flen-520-3.0406.pkg) few days back, i thought I was able to blocked psiphon completely but after a few minutes of waiting, psiphon successfully connected. whew!i started to scratched my head again ;)
Fortigate Newbie
Last Update Attempt: Tue Mar 21 12:24:18 2017
Result: No Updates
Botnet Domain Database
---------
Version: 1.00638
Contract Expiry Date: n/a
Last Updated using manual update on Tue Jan 10 11:02:00 2017
Last Update Attempt: n/a
Result: Updates Installed
Modem List
---------
Version: 0.000
Device and OS Identification
---------
Version: 1.00055
Contract Expiry Date: Thu Nov 29 2018
Last Updated using manual update on Fri Mar 3 23:15:00 2017
Last Update Attempt: Tue Mar 21 12:24:18 2017
Result: No Updates
IP Geography DB
---------
Version: 1.062
Contract Expiry Date: n/a
Last Update Date: Fri Mar 10 18:09:33 2017
Certificate Bundle
---------
Version: 1.00005
Last Update Date: Thu May 5 10:58:00 2016
FDS Address
---------
96.45.33.81-443
URL White list
---------
Version: 1.00618
Contract Expiry Date: Thu Nov 29 2018
Last Updated using scheduled update on Mon Mar 20 18:24:23 2017
Last Update Attempt: Tue Mar 21 12:24:18 2017
Result: No Updates
Primary_FortiGate #
I enable ssl deep inspection , but still user can bybass fortigate
nawaysa,
Your "diagnose autoupdate versions" is incomplete. I dont see any info about your IPS Engine and IPS Definition versions. Can you PM your configuration file to me and let me know which policy ID are you using?
Is there any new solution to block Psiphon?????
the only way is apply ssl deep inspection and install certificate in ALL computers in your network
The speed of the service is certainly acceptable, If you want to block this Psiphon VPN, you will must to block all VPN which are not yours.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1711 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.