This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

(SOLVED) Sophos allowed always psiphon 3 proxy

Hi dear friends,

I use Sophos XG in my company. Some users pass Sophos Web filter and Application Control with psiphon proxy 3 app. I create new rule Application Controll --> Deny All and Web Filter --> Default all block but psiphon proxy connecting. This is a big big so big problem. Soon all users begin use this program :) 

How disable this trouble program with Sophos XG



This thread was automatically locked due to age.
Parents
  • Hi,

    I ended up re-organising categories so that anonymises was in its own group then added that to blocked rule. Seems to work.

    Ian 

  • My rules... Never block

    This is a big touble for Sophos XG. Because Fortigate, Sonicwall application control blocked without any problem. I think sophos applicaton control dont work well 

    Web Rule --> Anonymizers - IP Address Blocked -- Allow All

    Application Control --> Proxy and Tunnel Blocked -- Allow All

     

  • Hi,

    I see what I think is one issue and that is you are using the default web filter, you need to change to specific/group categories. What you are trying to do is not part of the default web filter.

    I agree with you that mr7 application rules do not work straight out of the ISO and need to be tweaked. I have  no ads, malware and explicit nudity and added the other items into my firewall rule. The rule does work on about 95% of sites I trust against. Some ad sites are now seeking through, I suspect they have incorrectly categorised. One MAC blocks at the other doesn't bit confused by this and need to compare configuration.

     

    Ian

  • My Web Default Policy --> Anonymizer and IP ADDRESS categorizes blocked

    My App Policy Engelle --> Proxy and Tunnel - P2P Blocked 

    I think sophos app control cant work well so we can blocked this app 3 ways

    1. Blocked psiphon app uses ip address and web sites. 

    2. Adding Psiphon 3 siganture to IPS Custom Signatures. I dont known how can I learn app signature?

    3. Psiphon certificate blocked. I think best way it but how can I do?

  • I have opened Sophos Support ticked. They connected my system and be controlled. Fixed:

     

    Connecting Sophos Fw with putty.

    Device console and

    ips maxpkts 100

     

    And finished... Psipshon nightmare was finished. I want to say thanks Sophos Support Team

  • Hi Sir,

    Good Day

    What kind of configurations Sophos Support Team do to your firewall?

    Can you share it? Im having a problem also with Psiphon like application.

    Gracias

  • It is so easily

    You must connect firewall console with putty app.

    You choice 4 - Device Console,

    set ips maxpkts 100 

    and reboot firewall

Reply Children