USG40

Options
Hello everyone... i have usg40 and i want to block all vpn applications like psiphon...how to do this
«1

All Replies

  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,483  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    Hi @joudeh1996,
    Welcome to Zyxel community. :) You can block VPN service by App patrol.
    1) Go to CONFIGURATION >  UTM profile > App patrol, and select "Bypass_Proxies_and_Tunnels service" to create app profile.

    2) Apply app profile to security policy at CONFIGURATION  > Security Policy > LAN_Outgoing.

    Want a FREE Access Point? Participate in our campaign and share your network setup for a chance to win! https://bit.ly/3z9MJPB

  • mMontana
    mMontana Posts: 1,349  Guru Member
    Community MVP First Anniversary 10 Comments Friend Collector
    Options
    App patrol is a yearly payed service?
  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,483  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    Yep, it's yearly payed license service.

    Want a FREE Access Point? Participate in our campaign and share your network setup for a chance to win! https://bit.ly/3z9MJPB

  • joudeh1996
    Options
    After doing all the suggested steps
    PSIPHON  is still working
    Any suggestions?
  • PeterUK
    PeterUK Posts: 2,959  Guru Member
    Community MVP First Anniversary 10 Comments Friend Collector
    Options
    Did you select all?
    is service status active? 
     
  • joudeh1996
    Options
    yes i do
    Psiphon still working
  • SamerShream
    Options

    I have the same problem (PSIPHON  is still working)
     Please help



  • PeterUK
    PeterUK Posts: 2,959  Guru Member
    Community MVP First Anniversary 10 Comments Friend Collector
    Options

    So I decided to activate my Trial on Zywall 110 (updated the Signature) to block this Psiphon and even with only ports 80,443,53 to block this it was allowed. Now this is not surprising to me you can bypass anything to look like normal traffic.

    So what are your options...well you could block the IP of the servers which will take time to do and thats if they don't change over time.


  • Zyxel_Cooldia
    Zyxel_Cooldia Posts: 1,483  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    edited August 2022
    Options
    Hi @joudeh1996,
    We would like to conduct a lab test.
    Did you test on Mobile version(IOS/Android) or Windows Desktop version?

    Want a FREE Access Point? Participate in our campaign and share your network setup for a chance to win! https://bit.ly/3z9MJPB

  • joudeh1996
    Options
    How to update my signature?

Security Highlight