This article describe the recommended CLI settings for the application filter in order to better detect and block critical and evasive applications such as Psiphon, Tor Proxy (Tor Browser), Torrent, Ultrasurf, HotSpot Shield, etc.The following sections are covered:
Applies to the following Sophos products and versionsSophos Firewall and Cyberoam
show advanced-firewallshow ips-settings
set advanced-firewall midstream-connection-pickup offset ips maxsesbytes-settings update 0set ips maxpkts 80set ips packet-streaming on
Along with P2P and Proxy and Tunnel category, applications listed below must be denied in the application filter policy. In case of CROS Micro App should be enabled in Application filter Policy.
The same application filter policy (as configured above) must be applied to DNS Firewall rule as well, if there is any.
CLI + GUI Settings.
Hi,
interesting about the block unknown ssl traffic when the recommended default is to leave it off.
Ian
rfcat_vk said: interesting about the block unknown ssl traffic when the recommended default is to leave it off.
Maximum compatibility is to have it off.
Maximum protection is to have it on.
Most admins care more about compatibility and therefore have it off. That is the default and the recommendation. For some cases where admins are trying to block specific things, it needs to be on. Turning it on will help block Hot spot Shield Proxy, but will also block other things.