Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
zwilson50
New Contributor

VPN Blocking Best Practice

We are currently working through blocking VPN's on our FortiGate 600D.  It seems like we are spinning our wheels trying to chase down individual VPNs that our students are using to circumvent our security measures.  How are you all handling the blocking of mobile device VPNs at a macro level?  It doesn't seem feasible to chase down, block and test the hundreds of VPNs that are currently available.

 

Thanks for your input.

3 REPLIES 3
hmtay_FTNT
Staff
Staff

Hello zwilson50,

 

To block the VPNs, please set the category "Proxy" and the signatures "PPTP", "L2TP" and "ISAKMP" to Block. That should block most if not all the VPNs you can find.

 

As to how we try to cover all the VPNs, from our research, 80-90% of the common VPNs in the market use some forms of the OpenVPN protocol that our "OpenVPN" signature would block. For those that do not use the OpenVPN protocol, many share the same servers or API calls. This signature works for most of Android and Windows VPNs.

 

For iOS VPNs, because of strict restrictions by Apple that VPNs need to use PPTP, L2TP or IPSec (we name the signature ISAKMP), blocking those 3 signatures would block most of the VPNs on iOS.

 

The remaining VPNs that are not covered by the signatures above are covered by the other signatures in our Proxy category. We have our tools that monitor when these apps are updated and we update our signatures accordingly. We give special priority to certain very evasive VPNs like Ultrasurf, Psiphon, Hotspot Shield, Freegate, etc because they employ very complicated protocols to bypass firewalls.

 

HoMing

MarcAbaya

I have a similar problem, but I'm trying to block VPN clients that use SSL-TLS. What's the best way of doing this? We can't block SSL-TLS totally since it is used by browsers, etc.

AlletoGraciel90

How do we bypass this block, considering all VPN's have been blocked. Ultrasurf, Psiphon, Hotspot Shield, Freegate are also blocked with the help of a certificate installed in the device without which the wifi won't work. Can you please tell me if there is a way around all these blocks?

Labels
Top Kudoed Authors