<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Tor  Browser  how to block</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/126224/tor-browser-how-to-block</link><description>If I have already installed Tor browser y my PC with all administative permissions (or any one else in the company LAN) how can i block in the XG Firewall in order to no one use it?? 
 I already try using block proxy in App Control (deny all) .. but may</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Tor  Browser  how to block</title><link>https://community.sophos.com/thread/462156?ContentTypeID=1</link><pubDate>Fri, 26 Feb 2021 21:48:00 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:78a136c4-b879-484a-aa79-695c2172bf32</guid><dc:creator>rfcat_vk</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;from experience you will need full decrypt and scan along CA installation and use the web proxy because SSL/TLS in this version does not scan UDP traffic which TOR will use if it finds TCP blocked.&lt;/p&gt;
&lt;p&gt;You will also need to change from any service to http/s otherwise checking will fail.&lt;/p&gt;
&lt;p&gt;I have inspect all content enabled rather than just untrusted content.&lt;/p&gt;
&lt;p&gt;Ian&lt;/p&gt;
&lt;p&gt;Also what are your DOS settings/parameters as shown in the IPS tab?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Tor  Browser  how to block</title><link>https://community.sophos.com/thread/462109?ContentTypeID=1</link><pubDate>Fri, 26 Feb 2021 14:14:34 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:14ac747d-ec65-4b71-9d85-9883c64a289e</guid><dc:creator>FormerMember</dc:creator><description>&lt;p&gt;Hi &lt;a href="/members/atilio-servian"&gt;Atilio Servian&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;What is the firmware version on your firewall? If it&amp;rsquo;s 17.5, you need to turn on HTTPS scanning, and for V18, SSL/TLS inspection turned on; check out the provided document for more info. Also, run a packet capture on the source IP address to ensure that traffic is hitting the correct firewall rule.&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://support.sophos.com/support/s/article/KB-000035761?language=en_US" rel="noopener noreferrer" target="_blank"&gt;Monitor traffic using Packet Capture Utility in the Sophos XG Firewall GUI&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks,&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Tor  Browser  how to block</title><link>https://community.sophos.com/thread/462107?ContentTypeID=1</link><pubDate>Fri, 26 Feb 2021 14:02:08 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:e69ca17a-bf68-4559-b97a-9a879d63d322</guid><dc:creator>Atilio Servian</dc:creator><description>&lt;p&gt;Dear&amp;nbsp; H_Patel.&lt;/p&gt;
&lt;p&gt;I try to follow the settings as you recommend ...&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I change the parameters recommended&amp;nbsp; indicated (as the pictures below my XG Firewall)&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#000000;"&gt;&lt;code&gt;show advanced-firewall&lt;br /&gt;show ips-settings&lt;/code&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#000000;"&gt;&lt;code&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/126/pastedimage1614345590415v3.png" alt=" " /&gt;&lt;/code&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#000000;"&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/126/pastedimage1614345524418v2.png" alt=" " /&gt;&lt;code&gt;&lt;/code&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#000000;"&gt;&lt;code&gt;&lt;/code&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#000000;"&gt;&lt;code&gt;&lt;/code&gt;Please&amp;nbsp; Notice there are some diferences&amp;nbsp; with other&amp;nbsp; parameters but no with the recomended to change .... &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#000000;"&gt;I also create one Firewall Rule for one particular VLAN (test one)&amp;nbsp; including a&amp;nbsp; App control&amp;nbsp; Policy to block what was recommended &amp;nbsp; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#000000;"&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/126/pastedimage1614346066883v5.png" alt=" " /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#000000;"&gt;The App control Policy include and &lt;strong&gt;P2P&amp;nbsp;&lt;/strong&gt;and&amp;nbsp;&lt;strong&gt;Proxy and Tunnel&lt;/strong&gt;&amp;nbsp;category&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="color:#000000;"&gt;DNS Multiple QNAME&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="color:#000000;"&gt;OpenVPN&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="color:#000000;"&gt;QUIC&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="color:#000000;"&gt;Non-SSL/TLS traffic on port 443&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="color:#000000;"&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/126/pastedimage1614345801393v4.png" alt=" " /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#000000;"&gt;including others two categories&amp;nbsp; for&amp;nbsp; P2P&amp;nbsp;&amp;nbsp; and&amp;nbsp; Proxy and Tunnels ..... (no showed in the image above but included)&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#000000;"&gt;This App control Policy&amp;nbsp; was included in the same Firewall rule for the VLAN in test...&amp;nbsp;&amp;nbsp;&amp;nbsp; No other Rule included..... No web policy and&amp;nbsp; No IPS policy included (just what was show in IPS command settings &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#000000;"&gt;Tor still running ...&amp;nbsp; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#000000;"&gt;Do i miss Something ??&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#000000;"&gt;If some other parameters must be changed or include... please indicate the commands to do it .... &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#000000;"&gt;Thanks in advance &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#000000;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#000000;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Tor  Browser  how to block</title><link>https://community.sophos.com/thread/461902?ContentTypeID=1</link><pubDate>Wed, 24 Feb 2021 15:18:09 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:024f0eef-c8f5-4583-9d2a-176ad5274d9c</guid><dc:creator>FormerMember</dc:creator><description>&lt;p&gt;Hi &lt;a href="/members/atilio-servian"&gt;Atilio Servian&lt;/a&gt;,&lt;/p&gt;
&lt;p&gt;Thank you for reaching out to the Community!&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Check out the steps outlined in the following document to block Tor Proxy(Tor Browser).&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="/xg-firewall/f/recommended-reads/119051/sophos-xg-firewall-cyberoam-application-filter-recommended-settings-for-better-application-detection" rel="noopener noreferrer" target="_blank"&gt;Sophos XG Firewall / Cyberoam: Application filter recommended settings for better application detection&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks,&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>