Jump to content

Recommended Posts

Posted

Our delightful cherubs are using portable browsers with VPN over HTTPS plugins. The obvious boasters are caught easily, however the clever ones are sneaking under the radar by being quiet. We already MitM with a domain CA cert for HTTPS filtering (diladele/squid filtering), yes our policies have the MitM (for students, we don't MitM for staff) explained and we have a proxy bypass policy too - disciplining is only possible when you catch them. Is there a way of DPI/ALI dropping anything other than true web traffic? I assume the initial https handshake will be legit followed by VPN encrypted traffic afterwards? I can get my hands on a sonicwall 2400 device but am loathe to pay for the annual app control license (if that is what is needed). Our firewall is good old iptables on our Linux gateway so nothing fancy (but being Linux I can install software as appropriate).

 

I have never attempted DPI/ALI on Linux before (I miss our old ISA 2006 box, why did you stop it MS!)

Posted
How are they running portable browsers? can you stop it at source with some software restriction policies to prevent running programs from anywhere they can write to?
Posted (edited)

to our chagrin we run programming courses that generate .exe of their own. In the past we could control it when it was just gamemaker but now the 6th formers (and advanced 5th formers) are compiling .NET. I tried to experiment with the compilers running under a different user (and that user only having rights to write to folders) but you get into issues when that app has to read/write to "my documents" etc

 

the obvious answer is discipline of course but if someone had experimented in Linux then I'd be happy to borrow your notes.

Edited by KK20
Posted
Can you identify the domains which are being used to establish the HTTPS handshake and then block them? Lightspeed gave me a list of sites when I asked them (after our students started using VPNs on their BYODs); probably not appropriate to share it though...
Posted
I think i'll have to do that. Betternet uses amazon so that will be fun :-)

 

We have Betternet blocked here and Amazon definitely still works...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...