Jump to content

Recommended Posts

Posted

Hi All,

 

We temporarily have our guest Wi-Fi open to all students (previously just sixth form).

 

Looking at the daily reports I have set up in SmoothWall, I've noticed a sharp increase in traffic to IP hosts; and when you do a lookup to those hosts they link back to VPN companies such as M247.

 

Does anyone have a strategy for this? SmoothWall has a category for 'web proxies' which we block however I have a list of 12 IPs just from yesterday that aren't in this category. I've started to add them manually so that they are blocked, but clearly there will be hundreds and thousands of these across the various VPN apps and services available.

 

Is there a better way to filter these out?

 

I'm not worried about bandwidth as we rate limit them anyway but more concerned about bypassing our filtering.

 

Thanks!

Posted
Hi All,

 

We temporarily have our guest Wi-Fi open to all students (previously just sixth form).

 

Looking at the daily reports I have set up in SmoothWall, I've noticed a sharp increase in traffic to IP hosts; and when you do a lookup to those hosts they link back to VPN companies such as M247.

 

Does anyone have a strategy for this? SmoothWall has a category for 'web proxies' which we block however I have a list of 12 IPs just from yesterday that aren't in this category. I've started to add them manually so that they are blocked, but clearly there will be hundreds and thousands of these across the various VPN apps and services available.

 

Is there a better way to filter these out?

 

I'm not worried about bandwidth as we rate limit them anyway but more concerned about bypassing our filtering.

 

Thanks!

 

Block all direct ip connections, close all ports and force everything via the proxy.

Posted
Block all direct ip connections, close all ports and force everything via the proxy.

 

We do this already; the problem is the proxy's (SmoothWall) 'Web Proxy' category isn't fully featured enough to catch all the modern VPNs. I am adding them manually.

 

BYOD clients ONLY have access to the gateway IP (which is the transparent smoothwall proxy) on ports 80/443/53 and specific internal IPs we allow for on-site services such as printing and OWA.

Posted
You could try blocking ipsec and ports such as 1194 udp.

 

Or alternatively a NGFW may be able to block via application??

 

https://kb.smoothwall.com/hc/en-us/articles/360000894119-Blocking-NordVPN-

 

I'd also recommend limiting specific devices connect to external DNS. There is no need for a domain client to need access directly to external DNS for sure.

 

We only have port 80/443/53 open. All other ports are closed. These VPNs must be operating on port 80/443 as I can see the traffic via my SmoothWall.

Posted
For the transparent proxy, what method is set in the behaviour dropdown for the auth policy? You could try 'Block HTTPS with no SNI header' - it may interfere with some other apps on mobiles as well but general browsing works fine.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...