<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Vypr VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vypr-vpn/m-p/73947#M41574</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27949"&gt;@inzamam.shahid﻿&lt;/a&gt;&amp;nbsp;Ask and you shall receive. &amp;nbsp;It appears "vyprvpn" is now a recognized application per content update 564.&lt;/P&gt;</description>
    <pubDate>Tue, 01 Mar 2016 23:45:55 GMT</pubDate>
    <dc:creator>Brandon_Wertz</dc:creator>
    <dc:date>2016-03-01T23:45:55Z</dc:date>
    <item>
      <title>Vypr VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vypr-vpn/m-p/71439#M40791</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone used VYPR VPN. We are seeing users use this quiet a lot and they are bypassing the firewall to get onto whatever they want.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have submitted to PAN to create an application for this as one does not currently exist, but we need to block this in the mean time. I know we can create a custom application for this, but I am not experienced enough to put in the details for this so it only affects that application.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is creating a custom application the best way to block this or would anyone recommend another way ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2016 11:17:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vypr-vpn/m-p/71439#M40791</guid>
      <dc:creator>inzamam.shahid</dc:creator>
      <dc:date>2016-01-22T11:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: Vypr VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vypr-vpn/m-p/71465#M40805</link>
      <description>&lt;P&gt;While some of their VPN protocols are standards-based with corresponding AppIDs, I bet you're having problem with the "chameleon" variant. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you can't block it by AppID, you should be able to tackle this via FQDN address objects. &amp;nbsp;They've provided a complete list of their servers here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;-&amp;nbsp;&lt;A href="https://support.goldenfrog.com/hc/en-us/articles/203733723-What-are-the-VyprVPN-server-addresses-" target="_blank"&gt;https://support.goldenfrog.com/hc/en-us/articles/203733723-What-are-the-VyprVPN-server-addresses-&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The CLI will probably be the quickest way to get these entries in your firewall. &amp;nbsp;Here's what the commands would look:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;set address us1.vpn.goldenfrog.com tag vyprvpn&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;set address us1.vpn.goldenfrog.com fqdn us1.vpn.goldenfrog.com&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;set address us2.vpn.goldenfrog.com tag vyprvpn&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;set address us2.vpn.goldenfrog.com fqdn us2.vpn.goldenfrog.com&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Lather, rinse, repeat for each of the server locations. &amp;nbsp;When you're done it will start to look something like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2173i0E9C8065C190CE46/image-size/medium?v=mpbl-1&amp;amp;px=-1" border="0" alt="vypr1.PNG" title="vypr1.PNG" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You're tagging each of these objects with a "vyprvpn" tag for a good reason. &amp;nbsp;The above process will create one address object per server location. &amp;nbsp;You then create an Address Group that includes all of the individual address objects tagged with 'vyprvpn' like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2174i0BEF67AEB4E8E52E/image-size/medium?v=mpbl-1&amp;amp;px=-1" border="0" alt="vypr2.PNG" title="vypr2.PNG" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And finally, create a security policy that blocks traffic to 'vyprvpn-group' on any app and any port.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2175i747E90F8539B01A2/image-size/medium?v=mpbl-1&amp;amp;px=-1" border="0" alt="vypr3.PNG" title="vypr3.PNG" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EDIT: &amp;nbsp;I assumed that the VyprVPN server was hosted by goldenfrog.com in my above instructions. &amp;nbsp;You may need to do something similar for VyprVPN through giganews, ie: us1.vpn.giganews.com, but the concept is the same. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, I did a couple of quick tests.. &amp;nbsp;VyprVPN on iOS is detected as "ciscovpn" and "ipsec-esp-udp" from an AppID perspective. &amp;nbsp;Block those Apps to shut this down on that platform. &amp;nbsp;On Windows, the VyprVPN "Chameleon" protocol is detected as "unknown-udp" and can also be blocked. &amp;nbsp;In my lab, blocking unknown-udp prevented VyprVPN from establishing a Chameleon VPN tunnel without worrying about destination IP addresses.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2016 18:43:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vypr-vpn/m-p/71465#M40805</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2016-01-22T18:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: Vypr VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vypr-vpn/m-p/73947#M41574</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27949"&gt;@inzamam.shahid﻿&lt;/a&gt;&amp;nbsp;Ask and you shall receive. &amp;nbsp;It appears "vyprvpn" is now a recognized application per content update 564.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2016 23:45:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vypr-vpn/m-p/73947#M41574</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-03-01T23:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: Vypr VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vypr-vpn/m-p/73971#M41580</link>
      <description>&lt;P&gt;I saw that today glad it got created it makes things much simpler!&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2016 10:32:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vypr-vpn/m-p/73971#M41580</guid>
      <dc:creator>inzamam.shahid</dc:creator>
      <dc:date>2016-03-02T10:32:50Z</dc:date>
    </item>
  </channel>
</rss>

