Hi,
Can anyone share how we can block Psiphon app using XG IPS attack pattern?
Thanks,
Apollo
This thread was automatically locked due to age.
Hi,
Based on my experience on blocking psiphon in Sophos XG, first block it in the application control and web filtering then enable "decrypt and scan" in the policy where the traffic would pass and create a policy that would block outbound SSH connectivity.
Hope that helps, let us know if that worked for you.
Regards,
Rap
Create Application Filter with "Proxy and Tunnels" category selected
Create Web Filter with Anonymizers selected
SSH out allowed or disallowed both doesn't stop blocking Psiphon
Create Firewall Rule
RESULT:
1. Psiphon can still connected
2. ZenMate Blocked