Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Fullmoon
Contributor III

psiphon

now the headache backs again, anyone does the trick on how block psiphon? Im using  FGT 1000C and FGT 92D running in FOS 5.4.3 and 5.2.10 seems psiphon able to bypass. applied ssl deep inspection (select all ports), blocked botnet p2p and proxy under app control, blocked web proxy under web filter profile, even limits the service to http/s and dns still no glory.   anyone willing to share their tricks on how to block psiphon? thanks  IPS Definitions Version 10.00070 IPS Engine Version 3.00299

Fortigate Newbie

Fortigate Newbie
17 REPLIES 17
juancava

Any update on this? I have a FortiGate 500D with deep inspection. All clients have to use a certificate, but I can't block psiphon, even if it is blocked in application control. I'm managing a high school, and this is starting to become a very big problem.

Ashik_Sheik

Hi 

 

Any suggestions to block psiphon we can't use deep packet inspection due to current firewall architecture .

 

 

Sheik Mahammad Ashik
Sheik Mahammad Ashik
binnyrog

Why is Fortigate is not able to block Psiphon even with the application controls and deep packet inspection? It's giving me a headache going through the settings and blocking Psiphon. 

 

Did anyone get success in blocking the same?

Ashik_Sheik

The only other method I can think of is to block based on IP addresses. You may consider the ISDB (internet service database) and block based proxy IP category. Hoping that the addresses they use are part of this group.

 

Sheik Mahammad Ashik
Sheik Mahammad Ashik
cwb2205

I have a Fortgate 500E I just set up at at client running FortiOS 5.0.6. We have application control blocking all Proxy signatures which I have applied to their internet policies. I am seeing daily hits on the firewall blocking Psiphon. I just checked the signatures for application control and Psiphon is there. 

 

currently running app control version 14.00659

NSE 7 ATP3.0

NSE 7 ATP3.0
Shehroz
New Contributor

I have same issue since i install fortigate i'm unable to block psiphon vpn app but in the logs section of app control and web filter it is continue blocking but in the actual users are able to connect through psiphon on pc as well as on mobile using corporate wifi network. I was using fortiOS 5.6.8 and yesterday have upgraded to 5.6.9 but issue is the same it is showing block in app and web but not blocking in actual..

 

Any expert can give lead pl

geekmooc
New Contributor

want to know that, too

thanh
New Contributor

My problem is someones are using proxy/vpn mobile apps to access social media sites (like youtube and facebook), i can't find any way to restrict its !

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors