<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ultrasurf Blocking Fail in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45156#M33173</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Decryption is the key, it should always apply on any category and block sessions which cannot be decrypted (add exceptions to banking and governement sites + to few applications that don't support it).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you don't decrypt, there is no point in trying to block evasion applications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are some Tor/Ultrasurlf app providers which change their URLs everyday. Some of them are just providing a plain old openvpn client thats runs over SSL (boxpn for example).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used to make filtering policies that were hard (if not impossible) to escape by my users with PAN products. SSL decryption is the key with an adapted AppID policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 24 Mar 2014 17:32:06 GMT</pubDate>
    <dc:creator>cpainchaud</dc:creator>
    <dc:date>2014-03-24T17:32:06Z</dc:date>
    <item>
      <title>Ultrasurf Blocking Fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45131#M33148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am suferring from many failed attempts trying to block ultrasurf. i added the application to a deny policy on the top of my policies, but users keeps jumping to the allow policy. i tried to block unkown UDP/TCP apps, but it failed too. the applcation itself can't be blocked even though i blocked all the dependecies. i tried to do it on 5050 and 5060 on both PAN 5.0.11 and PAN-OS 6.0 with the most updated licenses.can some one help. i guess it's considered a huge problem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Feb 2014 16:38:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45131#M33148</guid>
      <dc:creator>Mohammad</dc:creator>
      <dc:date>2014-02-23T16:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: Ultrasurf Blocking Fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45132#M33149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Few related discussions, it might help you:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/25313"&gt;Re: How to block Ultrasurf?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/35556"&gt;Re: Ultrasurf 13.03 appearing as unknown-tcp&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/27277"&gt;Re: unknown-tcp / udp - please explain&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Feb 2014 18:27:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45132#M33149</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-02-23T18:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: Ultrasurf Blocking Fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45133#M33150</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is an open case for that.It is not fixed yet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Feb 2014 09:01:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45133#M33150</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-02-24T09:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: Ultrasurf Blocking Fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45134#M33151</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please update the case ID here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Feb 2014 09:34:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45134#M33151</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-02-24T09:34:52Z</dc:date>
    </item>
    <item>
      <title>Re: Ultrasurf Blocking Fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45135#M33152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://na5.salesforce.com/5007000000XZ5vL"&gt;00171473&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks for help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Feb 2014 09:37:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45135#M33152</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-02-24T09:37:11Z</dc:date>
    </item>
    <item>
      <title>Re: Ultrasurf Blocking Fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45136#M33153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Engineering is still working on this BUG. Fix is not available yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Feb 2014 10:25:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45136#M33153</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-02-24T10:25:40Z</dc:date>
    </item>
    <item>
      <title>Re: Ultrasurf Blocking Fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45137#M33154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the same story with kproxy and freegate !!!:smileyshocked:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Feb 2014 11:26:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45137#M33154</guid>
      <dc:creator>malswealmeen</dc:creator>
      <dc:date>2014-02-24T11:26:40Z</dc:date>
    </item>
    <item>
      <title>Re: Ultrasurf Blocking Fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45138#M33155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does it still happen with Decryption enabled and Block sessions that cannot decrypted ? With that my own tests show it cannot get through .... Also it's useless to say unknown-tcp and unknown-udp should be blocked ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Feb 2014 16:53:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45138#M33155</guid>
      <dc:creator>cpainchaud</dc:creator>
      <dc:date>2014-02-24T16:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: Ultrasurf Blocking Fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45139#M33156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12px; background-color: #f6f6f6;"&gt; unknown-tcp and unknown-udp are blocked but should the PA block them without the need of ssl decryption policy ( i mean if we have the right signature of the application) ?!&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Feb 2014 20:23:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45139#M33156</guid>
      <dc:creator>malswealmeen</dc:creator>
      <dc:date>2014-02-26T20:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: Ultrasurf Blocking Fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45140#M33157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;with ssl decryption you will identify the real app. inside the ssl, so if you see only unknown tcp/udp , after decryption it will not change.&lt;/P&gt;&lt;P&gt;But if you see ssl, then it may change.&lt;/P&gt;&lt;P&gt;Until last version of ultrasurf, we were able to block it without decryption.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Feb 2014 20:56:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45140#M33157</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-02-26T20:56:13Z</dc:date>
    </item>
    <item>
      <title>Re: Ultrasurf Blocking Fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45141#M33158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe you have already opened a case but incase you have not i would recommend opening a case with support with the following information&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Application version of Ultrasurf&lt;/P&gt;&lt;P&gt;2. pcap of the traffic from the client side&lt;/P&gt;&lt;P&gt;3. traffic logs during your testing&lt;/P&gt;&lt;P&gt;4. techsupport file&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Feb 2014 20:57:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45141#M33158</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2014-02-26T20:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: Ultrasurf Blocking Fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45142#M33159</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is not wokring with last version&lt;/P&gt;&lt;P&gt;even using a decryption profile, ultrasurf works.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Feb 2014 08:01:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45142#M33159</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-02-27T08:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: Ultrasurf Blocking Fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45143#M33160</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have followed on the issue. This currently being investigated by engineering team. &lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Feb 2014 18:31:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45143#M33160</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2014-02-27T18:31:24Z</dc:date>
    </item>
    <item>
      <title>Re: Ultrasurf Blocking Fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45144#M33161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems ultrasurf has updated it's proxy network. based from the current version 13.04, PAN detects Ultrasurf and denies it. however it passes thru for some weird reasons and now the software calls for HE.NET which resides in the USA. i have responded to an older query regarding Ultrasurf but during that time, the software calls / connect to Taiwan (HINET) which i stated to block the whole country to prevent ultrasurf from connecting. What you can do for now is to double check your filters and make sure ultrasurf and unknown-tcp are on your app block-list. This may not be full proof but it can slow "ultrasurf" to a crawl (for the mean time). which i'm doing right now. Let's hope PAN team can resolve this quickly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Mar 2014 09:56:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45144#M33161</guid>
      <dc:creator>Kali</dc:creator>
      <dc:date>2014-03-04T09:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: Ultrasurf Blocking Fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45145#M33162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Same problem with TOR.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Mar 2014 10:45:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45145#M33162</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2014-03-04T10:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: Ultrasurf Blocking Fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45146#M33163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My suggestion for all evasive apps like Ulrtrasurf, Tor, etc. is to open a support case when you find failure to block reliably. These apps are constantly evolving to try and evade control (evasive!). Once you have a support case open upload packet captures of the evasive traffic )capture it locally in your network) to the case. In many cases we find interesting regional differences in the application's evasion tactics. Having packet captures from your particular location is almost always a great help in determining what the app developer has added to the mix to try to fly under the radar.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Mar 2014 17:28:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45146#M33163</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2014-03-04T17:28:31Z</dc:date>
    </item>
    <item>
      <title>Re: Ultrasurf Blocking Fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45147#M33164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tested this on my firewall with latest App version (421) and it is being denied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hari Yadavalli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Mar 2014 17:44:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45147#M33164</guid>
      <dc:creator>hyadavalli</dc:creator>
      <dc:date>2014-03-04T17:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: Ultrasurf Blocking Fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45148#M33165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;for the time being we blocked the proxies as follow :&lt;/P&gt;&lt;P&gt;1-ssl decryption&lt;/P&gt;&lt;P&gt;2-block unknown App&lt;/P&gt;&lt;P&gt;3-block unknown url's&lt;/P&gt;&lt;P&gt;plus the app policy to deny the proxy software&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Mar 2014 19:41:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45148#M33165</guid>
      <dc:creator>malswealmeen</dc:creator>
      <dc:date>2014-03-04T19:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: Ultrasurf Blocking Fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45149#M33166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try the following for TOR:&lt;/P&gt;&lt;P&gt;1- Enable SSl decryption if you don't want create&amp;nbsp; a policy with SSL as application and in the url profile block the unknown sites.&lt;/P&gt;&lt;P&gt;2-second policy to block TOR by deny application&lt;/P&gt;&lt;P&gt;3-block the unknown App also&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Mar 2014 19:52:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45149#M33166</guid>
      <dc:creator>malswealmeen</dc:creator>
      <dc:date>2014-03-04T19:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: Ultrasurf Blocking Fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45150#M33167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you should also set block on SSL sessions which can't be decrypted (in decryption profile). Ultrasurf makes use of unsupported/unexisting SSL protocol options.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Mar 2014 23:55:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ultrasurf-blocking-fail/m-p/45150#M33167</guid>
      <dc:creator>cpainchaud</dc:creator>
      <dc:date>2014-03-04T23:55:58Z</dc:date>
    </item>
  </channel>
</rss>

