<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Decryption or blocking NordVPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-or-blocking-nordvpn/m-p/488387#M104814</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Decrypting would break the VPN connection. You would be better off blocking it like you are attempting to do. Check for the following applications, these are the typical apps identified for vpn client traffic.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://applipedia.paloaltonetworks.com/" target="_blank"&gt;https://applipedia.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1652911638730.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41054iD8BEF2ECF2287332/image-size/medium?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1652911638730.png" alt="OtakarKlier_0-1652911638730.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also make sure to have a DENY ALL policy and only allow the traffic you want. This is always the tough one to implement since there are so many pieces to the puzzle.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Wed, 18 May 2022 22:11:10 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2022-05-18T22:11:10Z</dc:date>
    <item>
      <title>Decryption or blocking NordVPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-or-blocking-nordvpn/m-p/488205#M104792</link>
      <description>&lt;P&gt;Is it possible for Palo Alto Firewall to decrypt&amp;nbsp;third party VPN agent traffic such as&amp;nbsp;NordVPN, NordLynx like decrypt HTTPS web-browsing traffic?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it cannot decrypt these traffic, anyone know the App-ID for&amp;nbsp;NordVPN, NordLynx?&lt;/P&gt;&lt;P&gt;I found some VPN app-ID like ciscovpn, open-vpn but no Nord related. What App-ID should I use to block NordVPN, NordLynx?&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 13:36:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-or-blocking-nordvpn/m-p/488205#M104792</guid>
      <dc:creator>JoeKwok</dc:creator>
      <dc:date>2022-05-18T13:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption or blocking NordVPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-or-blocking-nordvpn/m-p/488387#M104814</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Decrypting would break the VPN connection. You would be better off blocking it like you are attempting to do. Check for the following applications, these are the typical apps identified for vpn client traffic.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://applipedia.paloaltonetworks.com/" target="_blank"&gt;https://applipedia.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1652911638730.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41054iD8BEF2ECF2287332/image-size/medium?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1652911638730.png" alt="OtakarKlier_0-1652911638730.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also make sure to have a DENY ALL policy and only allow the traffic you want. This is always the tough one to implement since there are so many pieces to the puzzle.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 22:11:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-or-blocking-nordvpn/m-p/488387#M104814</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-05-18T22:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption or blocking NordVPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-or-blocking-nordvpn/m-p/488435#M104818</link>
      <description>&lt;P&gt;Thanks for you reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can found some VPN client App-ID, but it seems like no&amp;nbsp;&lt;SPAN&gt;NordVPN. Would you know the App-ID can block this VPN?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 02:39:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-or-blocking-nordvpn/m-p/488435#M104818</guid>
      <dc:creator>JoeKwok</dc:creator>
      <dc:date>2022-05-19T02:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: Decryption or blocking NordVPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/decryption-or-blocking-nordvpn/m-p/488675#M104842</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We take the opposite approach here. We block everything and only allow things by exception. So its already blocked, but not by a particular app/url/ip address. Its blocked by my DENY ALL policy. You would have to know how they work and check the destination IP's and or ports used to block that particular service. However the question to ask is, why would someone from inside your network need to access a third party VPN provider?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 20:00:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/decryption-or-blocking-nordvpn/m-p/488675#M104842</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-05-19T20:00:03Z</dc:date>
    </item>
  </channel>
</rss>

