Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ramesh_M
New Contributor

how to block ultrasurf 13.01 version

Hi, I have blocked all proxy applications in application control list. But still opening the latest versions of ultrasurf. It can block ultrasurf 10.2 versions. Tried to block using custom signatures as well but still not blocking. IOS versions is 4.0 mr3 patch 12. Please help me to sorted it out.

Ramesh M Technical Specialist - CCNA(Security), FCNSP, ACE, ASE, ITIL blogs.itzecuriry.in

Ramesh M Technical Specialist - CCNA(Security), FCNSP, ACE, ASE, ITIL blogs.itzecuriry.in
9 REPLIES 9
Dave_Hall
Honored Contributor

The entry for Ultrasurf_9.6+ on the FortGuard website indicates you also need to block " Freegate.Searching" as well.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Ramesh_M

Hi, I have blocked all the proxy applications. still I am not able to block..

Ramesh M Technical Specialist - CCNA(Security), FCNSP, ACE, ASE, ITIL blogs.itzecuriry.in

Ramesh M Technical Specialist - CCNA(Security), FCNSP, ACE, ASE, ITIL blogs.itzecuriry.in
Dave_Hall
Honored Contributor

Please review this KB article; it also mentions needing to apply the app sensor to DNS traffic (besides applying it to web traffic). It is suggested in one of the KB articles (re ultrasurf) to contact Fortinet support if you are still having problems blocking this app.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Ramesh_M
New Contributor

Dear Dave, In our network we are using Internal DNS server in the internal network.

Ramesh M Technical Specialist - CCNA(Security), FCNSP, ACE, ASE, ITIL blogs.itzecuriry.in

Ramesh M Technical Specialist - CCNA(Security), FCNSP, ACE, ASE, ITIL blogs.itzecuriry.in
ede_pfau
SuperUser
SuperUser

But your internal DNS must eventually connect to your ISP' s DNS on the net. Apply the AppControl profile to the policy which allows DNS requests to the outside.

Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Sachin8094
New Contributor

Hi, I am also facing the same issue, i have the same version and patch is running on the box. Please help us out for the same
FCNSA
FCNSA
Teemo
New Contributor

Is ssl deep scanning Enabled ?
TeemO
TeemO
Lyndon
New Contributor

Hi Ramesh M,

We have the same problem here we already block the ultrasurf application, but ultrasurf chrome extension we are not able to block it. until now we have no idea on how to block this things.

 

i hope there will be a fortiSuperMan that will help us. :D

 

regards,

lyndon

 

hmtay_FTNT

Hello,

 

If anyone finds the Ultrasurf_9.6+ signature not blocking for now, can you let me know? If you are using FortiOS 5.4 and above, our IPS engine now has the ability to block Ultrasurf without deep-inspection.

 

HoMing

Labels
Top Kudoed Authors