Betternet VPN

Author
Jasonhilt
Bronze Member
  • Total Posts : 21
  • Scores: 0
  • Reward points: 0
  • Joined: 2013/01/24 08:14:07
  • Status: offline
2016/12/14 10:26:41 (permalink)
0

Betternet VPN

Was recently notified that students are able to use the Betternet VPN app on their phones over our wireless to bypass the webfilter.  I have checked analyzer logs and it does block the website but not the IPs that the app is connecting to.
I have checked the school computers and everything seems to be blocked and the Chrome extension doesn't work.
 
Anyone know how to block this when it's used on a non-school owned device/personal device?  I have tried blocking individual IPs with some success, but not 100%.  Only issue is I don't know what other websites will be blocked in the process.
 
We have a Fortigate 1240B running v5.2.5 build 701
 
#1

8 Replies Related Threads

    SCSIraidGURU
    Silver Member
    • Total Posts : 97
    • Scores: 0
    • Reward points: 0
    • Joined: 2014/12/10 16:11:59
    • Status: offline
    Re: Betternet VPN 2016/12/14 12:05:46 (permalink)
    0
    Did you block it under application control Proxy?  Look at blocking PPTP VPNs. 
    #2
    Jasonhilt
    Bronze Member
    • Total Posts : 21
    • Scores: 0
    • Reward points: 0
    • Joined: 2013/01/24 08:14:07
    • Status: offline
    Re: Betternet VPN 2016/12/14 12:38:00 (permalink)
    0
    So I setup a policy just for my iPhone to test with.
    All application categories are blocked - vpn still connects.
    All FortiGuard Categories are blocked - vpn still connects.
    Individual IPs that I THINK might have something to do with the vpn are blocked - vpn still connects.
     
    I am at a loss how it's getting through.
     
    edit:
    I have tried Proxy, Flow-based and DNS on the Web Filter policy with no change.
     
    post edited by Jasonhilt - 2016/12/14 12:46:05
    #3
    SCSIraidGURU
    Silver Member
    • Total Posts : 97
    • Scores: 0
    • Reward points: 0
    • Joined: 2014/12/10 16:11:59
    • Status: offline
    Re: Betternet VPN 2016/12/14 13:20:13 (permalink)
    0
    Did you add it to Application Signatures as a block rule?  Betternet.vpn block also is all of Proxy listed as block?   What is your application control rule in the wireless policy set to default?   Can you create a custom policy? 
    #4
    SCSIraidGURU
    Silver Member
    • Total Posts : 97
    • Scores: 0
    • Reward points: 0
    • Joined: 2014/12/10 16:11:59
    • Status: offline
    Re: Betternet VPN 2016/12/14 13:21:33 (permalink)
    0
    Can you find the traffic in the logs getting though?  What does it say about the destination? 
    #5
    Jasonhilt
    Bronze Member
    • Total Posts : 21
    • Scores: 0
    • Reward points: 0
    • Joined: 2013/01/24 08:14:07
    • Status: offline
    Re: Betternet VPN 2016/12/15 10:49:35 (permalink)
    0
    So I figured out how it was getting past the firewall.  There was a policy that was implemented, not by me of course, that opened up the WiFi Calling service to and from the whole network.  It was set as the first policy and all the student policies are much lower on the list and lower on the page.  I didn't see it until I started moving my test policy up towards the top.
     
    So for future reference to anyone else having this issue:  WiFi Calling service will/can allow VPNs to bypass any other restrictions you have set.
    #6
    SCSIraidGURU
    Silver Member
    • Total Posts : 97
    • Scores: 0
    • Reward points: 0
    • Joined: 2014/12/10 16:11:59
    • Status: offline
    Re: Betternet VPN 2016/12/15 11:01:31 (permalink)
    0
    35 years of dealing with firewalls and Cisco routers taught me a great rule.
    1.) Deny before Allow!
     
    CISCO ACLs and firewalls work in rule order.  So place your deny rules first.  Place your allow rules after.  I want to block something, top of policy or ACL lists.  I want to put in a partial allow and then deny everything.  Put the partial allow ahead of the complete deny rule. 

    With Fortinet you need outbound rules for traffic to get out to the internet.  They go at the bottom of the policy list by interface.  SSL-VPN and Wifi below them.  Any deny rules above all these.  
     
     
    #7
    ABell
    New Member
    • Total Posts : 1
    • Scores: 0
    • Reward points: 0
    • Joined: 2016/12/16 07:08:09
    • Status: offline
    Re: Betternet VPN 2016/12/16 07:24:11 (permalink)
    0
    I'd like to try this.  What specific service am I looking for?
    #8
    SCSIraidGURU
    Silver Member
    • Total Posts : 97
    • Scores: 0
    • Reward points: 0
    • Joined: 2014/12/10 16:11:59
    • Status: offline
    Re: Betternet VPN 2016/12/16 08:04:46 (permalink)
    0
    Security Profiles
    Application Control
    You will see Proxy
    Under that is Betternet.VPN.

    You can make an Application Override and add it to the block.
     
    You can get all the IP addresses for Betternet.vpn and build a custom policy to block the traffic to this.  You might also look at PPTP VPN policy and block that.  You place these at the top of the list.   You need these outbound from your users to them. 
    #9
    Jump to:
    © 2021 APG vNext Commercial Version 5.5