<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to block Ultrasurf? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-ultrasurf/m-p/32550#M23845</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ive also opened a couple of ticket for this issue before...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;im using ultrasurf 1210....this issue makes some of our customer starting to doubt with PA :smileysilly:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 21 Mar 2013 14:58:07 GMT</pubDate>
    <dc:creator>afiq</dc:creator>
    <dc:date>2013-03-21T14:58:07Z</dc:date>
    <item>
      <title>How to block Ultrasurf?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-ultrasurf/m-p/32546#M23841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i create a rule to block Ultrasurf on top and a rule to allow any below it. but ultrasurf still can bypass. surprisingly once ultrasurf connected to its server, PAN unable to logged the traffic. No traffic looged in URL filtering, Threat and Traffic log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this tested on 4.1.x to 5.0.x with the latest content definition.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;anyone can share some experience?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tq.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 11:12:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-ultrasurf/m-p/32546#M23841</guid>
      <dc:creator>afiq</dc:creator>
      <dc:date>2013-03-21T11:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to block Ultrasurf?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-ultrasurf/m-p/32547#M23842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you replicate this issue with clearing all sessions and adding unkowsn tcp/udp to that rule ?&lt;/P&gt;&lt;P&gt;if this works then PA support has to check out for app update.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 11:39:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-ultrasurf/m-p/32547#M23842</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-03-21T11:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to block Ultrasurf?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-ultrasurf/m-p/32548#M23843</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;my first solution is clearing the session browser, but this only works temporary..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and currently im applying the same method like yours, create a block rule for unknown-tcp with port 443 ...this will block ultrasurf user from browsing any site but in the ultrasurf status is still 'succesfully connected'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i&amp;nbsp; just wonder how long PA going to update their Apps, ive been waiting for months for this issue. &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 14:27:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-ultrasurf/m-p/32548#M23843</guid>
      <dc:creator>afiq</dc:creator>
      <dc:date>2013-03-21T14:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to block Ultrasurf?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-ultrasurf/m-p/32549#M23844</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we have opened a case for this before.After a while they fixed it with an app version.But I did not test it nowadays.&lt;/P&gt;&lt;P&gt;I'll test it with last version.What is the version of ultrasurf you are using ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 14:31:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-ultrasurf/m-p/32549#M23844</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-03-21T14:31:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to block Ultrasurf?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-ultrasurf/m-p/32550#M23845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ive also opened a couple of ticket for this issue before...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;im using ultrasurf 1210....this issue makes some of our customer starting to doubt with PA :smileysilly:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 14:58:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-ultrasurf/m-p/32550#M23845</guid>
      <dc:creator>afiq</dc:creator>
      <dc:date>2013-03-21T14:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to block Ultrasurf?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-ultrasurf/m-p/32551#M23846</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you have enabled SSL-termination (SS-decrypt)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which appid does your PA identify this session with?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As debug enable both "log on session start" AND "log on session end" for all rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Apr 2013 20:36:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-ultrasurf/m-p/32551#M23846</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-04-01T20:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to block Ultrasurf?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-ultrasurf/m-p/32552#M23847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i just use 2 simple rule for testing purpose&lt;/P&gt;&lt;P&gt;1.Block Ultrasurf&lt;/P&gt;&lt;P&gt;2.Allow Any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.Enabled SSL decryption&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;in monitor&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;those app detected as Ultrasurf is blocked&lt;/LI&gt;&lt;LI&gt;443 decrypt as it should&lt;/LI&gt;&lt;LI&gt;and i can see some unknown-tcp and insufficient data&lt;/LI&gt;&lt;LI&gt;In URL log, some unknown category url can be seen&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;temp solution&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;create rule to block unknown-tcp with port 443&lt;/LI&gt;&lt;LI&gt;block Unknown URL category&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;im still waiting for PAN to update on this..:smileycry:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Apr 2013 03:05:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-ultrasurf/m-p/32552#M23847</guid>
      <dc:creator>afiq</dc:creator>
      <dc:date>2013-04-05T03:05:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to block Ultrasurf?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-ultrasurf/m-p/32553#M23848</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When ultrasurf updates to a new version, PAN only recognize the APP as ssl. What i've noticed though is that ultrasurf calls to TAIWAN(hi-net) network, a dynamic network. So what i did was i created a rule that blocks TAIWAN &amp;amp; unknown-tcp. Problem solved for Ultrasurf.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Apr 2013 00:33:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-ultrasurf/m-p/32553#M23848</guid>
      <dc:creator>Kali</dc:creator>
      <dc:date>2013-04-13T00:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to block Ultrasurf?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-ultrasurf/m-p/32554#M23849</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the rule to block unknown tcp for ultrasurf is a success.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but for high level/management views from all of my customers, they seems cant accept the the fact that PAN unable to block ultrasurf by using App-ID alone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the ultrasurf v12 has been released since last year and yet still no update to block this thing. &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Apr 2013 03:09:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-ultrasurf/m-p/32554#M23849</guid>
      <dc:creator>afiq</dc:creator>
      <dc:date>2013-04-29T03:09:04Z</dc:date>
    </item>
  </channel>
</rss>

