Hi,
Can anyone share how we can block Psiphon app using XG IPS attack pattern?
Thanks,
Apollo
This thread was automatically locked due to age.
Hi,
Based on my experience on blocking psiphon in Sophos XG, first block it in the application control and web filtering then enable "decrypt and scan" in the policy where the traffic would pass and create a policy that would block outbound SSH connectivity.
Hope that helps, let us know if that worked for you.
Regards,
Rap
You will need to setup a seperate rule for your mail clients to reduce the affects of decrypt and scan.
Outlook mail will fail with decrypt and scan and will not pass your mail rule, but will go through your general rule. The mail decrypt and scanning is limited to ports provided by Sophos so you can't use other ports.
Ian
You will need to setup a seperate rule for your mail clients to reduce the affects of decrypt and scan.
Outlook mail will fail with decrypt and scan and will not pass your mail rule, but will go through your general rule. The mail decrypt and scanning is limited to ports provided by Sophos so you can't use other ports.
Ian