Hi guys,
I have been trying to block the hotspot shield and Betternet VPN. I have included them in the Applications Filter.
I created a support ticket with Sophos and we were able to block the said applications by decrypting HTTPS using web proxy. It is also blocking other applications like Facebook, Instagram, etc. I can't deploy CA certificates on the end devices for HTTPS decryption.
The client is able to download the applications and use them. The firewall isn't blocking the hotspot shield and Betternet VPN traffic.
I am looking for a way to block those applications using DPI/Applications Filter. These apps use TCP, 443 port.
I am using an XGS 136.
Hi Vineeth Penugonda
Please check by creating the DNS service base firewall rule as shown below and create separate application filter policy to block high risk application as per link and apply on same
Please check by creating the DNS service base firewall rule as shown below and create separate application filter policy to block high risk application as per link and apply on same DNS service base firewall rule.
Please try the below steps too in case the application still not getting blocked :
show advanced-firewallshow ips-settings
set advanced-firewall midstream-connection-pickup offset ips maxsesbytes-settings update 0set ips maxpkts 80set ips packet-streaming on
Along with P2P and Proxy and Tunnel category, applications listed below must be denied in the application filter policy. In case of CROS Micro App should be enabled in Application filter Policy.
The same application filter policy (as configured above) must be applied to DNS Firewall rule as well, if there is any.
Thanks and Regards
Hi Bharat,
I tested with all the settings you provided. I am able to block "Hotspot Shield" by blocking "www.hsselite.com" and blocking "Risk 4 and Risk 5 apps" in the applications filter.
Interestingly, the Applications Filter detects the Hostspot Shield as "Facebook Website". (Attached Screenshot).
Sometimes, Psiphon Proxy is detected by the Applications Filter and blocks it. Users are still able to use "Psiphon Proxy" and "Betternet VPN".