Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Fullmoon
Contributor III

psiphon

now the headache backs again, anyone does the trick on how block psiphon? Im using  FGT 1000C and FGT 92D running in FOS 5.4.3 and 5.2.10 seems psiphon able to bypass. applied ssl deep inspection (select all ports), blocked botnet p2p and proxy under app control, blocked web proxy under web filter profile, even limits the service to http/s and dns still no glory.   anyone willing to share their tricks on how to block psiphon? thanks  IPS Definitions Version 10.00070 IPS Engine Version 3.00299

Fortigate Newbie

Fortigate Newbie
17 REPLIES 17
hmtay_FTNT
Staff
Staff

Hello,

 

Can you update your IPS Definition to 10.00071 or above. An update on the Psiphon signature was released in 10.00071 to cover the recent update. 

 

On the same topic, with IPS Engine 3.00299 and FortiOS 5.4 and above, our Psiphon signature does not require SSL deep-inspection anymore. We have added a new feature into the engine that allows us to block it without deep inspecting the packet.

nawaysa

I have update IPS and FOS but still Psiphone can bybass the fortigate?? any help please

 

hmtay_FTNT

Did you enable certificate-inspection or deep-inspection? Can you show me the output to the CLI command "diagnose autoupdate versions? Can you send me your configuration file in a PM? Thanks.

 

HoMing

Fullmoon

dear hmtay_FTNT,

TAC sent me IPS signature FOS 5.2.10 (flen-520-3.0406.pkg) few days back, i thought I was able to blocked psiphon completely but after a few minutes of waiting, psiphon successfully connected. whew!i started to scratched my head again ;)

 

Fortigate Newbie

Fortigate Newbie
nawaysa

Last Update Attempt: Tue Mar 21 12:24:18 2017
Result: No Updates
 
Botnet Domain Database
---------
Version: 1.00638
Contract Expiry Date: n/a
Last Updated using manual update on Tue Jan 10 11:02:00 2017
Last Update Attempt: n/a
Result: Updates Installed
 
Modem List
---------
Version: 0.000
 
Device and OS Identification
---------
Version: 1.00055
Contract Expiry Date: Thu Nov 29 2018
Last Updated using manual update on Fri Mar  3 23:15:00 2017
Last Update Attempt: Tue Mar 21 12:24:18 2017
Result: No Updates
 
IP Geography DB
---------
Version: 1.062
Contract Expiry Date: n/a
Last Update Date: Fri Mar 10 18:09:33 2017
  
Certificate Bundle
---------
Version: 1.00005
Last Update Date: Thu May  5 10:58:00 2016
  
FDS Address
---------
96.45.33.81-443
  
URL White list
---------
Version: 1.00618
Contract Expiry Date: Thu Nov 29 2018
Last Updated using scheduled update on Mon Mar 20 18:24:23 2017
Last Update Attempt: Tue Mar 21 12:24:18 2017
Result: No Updates
 
Primary_FortiGate # 

 

I enable ssl deep inspection , but still user can bybass fortigate

hmtay_FTNT

nawaysa,

 

Your "diagnose autoupdate versions" is incomplete. I dont see any info about your IPS Engine and IPS Definition versions. Can you PM your configuration file to me and let me know which policy ID are you using? 

nawaysa

Is there any new solution to block Psiphon?????

juanchonica
New Contributor

the only way is apply ssl deep inspection and install certificate in ALL computers in your network

Itsmejerry04
New Contributor

The speed of the service is certainly acceptable, If you want to block this Psiphon VPN, you will must to block all VPN which are not yours.

Labels
Top Kudoed Authors