FLEX500: Application Patrol: HideMyAss, x-vpn and Psiphon false positives?

Options
t80
t80 Posts: 2 image  Freshman Member

Hello,
I'm experiencing a strange issue for the last 3-4 weeks as my FLEX500 is logging HideMyAss, x-vpn and Psiphon outgoing connections from many windows 10 and windows 11 lan computers.

These connections are vs specific public ips, ports 80 and 443, i.e. :

HideMyAss
52.21.115.110
34.111.175.102
34.160.176.28
44.220.123.14
35.186.243.246

x_vpn
20.101.38.191
51.89.9.254
178.250.1.12

Psiphon
51.89.9.252

I blocked outgoing connections to these ips and app patrol block no longer triggers.

I checked my PCs on LAN and none has HideMyAss, x_vpn, Psiphon or other vpn clients installed or running.

Is anyone experiencing the same issue?

Thank You,
t80

All Replies

  • Zyxel_Tina
    Zyxel_Tina Posts: 855 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers 500 Comments

    Hi @t80,

    Welcome to the Zyxel Community!

    To further investigate the issue, we would appreciate your assistance in capturing packet when the issue occurs for analysis.

    Please capture packets from:

    • The USG FLEX 500
    • The affected Windows PC(s)

    After collecting the files, please provide the following information via private message by clicking my profile > Message:

    • The packet capture files
    • The approximate timestamp when the detection occurred
    • The source IP address of the affected client PC(s)

    This information will help us verify the behavior. Thank you for your cooperation!

    Zyxel Tina

  • fedebros
    fedebros Posts: 17 image  Freshman Member
    First Comment Friend Collector

    Hi @t80 I noticed similar issues with x_vpn . If happens again I will collect more information.