<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Blocking Hexa Protocol (Hexatech VPN) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-hexa-protocol-hexatech-vpn/m-p/79079#M43140</link>
    <description>&lt;P&gt;I just became aware of this yesterday, but we were seeing a rise recently in "unknown-udp" traffic on our Palo Alto Firewalls and have discovered what it was.&amp;nbsp; The amount of traffic was significant - always used the more bandwidth than anything else on the network.&amp;nbsp; There is a new-ish VPN service by BetterNet that uses a protocol called "Hexa" (&lt;A href="https://www.betternet.co/hexatech-vpn" target="_blank"&gt;https://www.betternet.co/hexatech-vpn&lt;/A&gt;) and is free to install on Android and IOS devices.&amp;nbsp; It tunnels 100% over UDP on randomized ports to over 2300 IP addresses that we've been able to isolate.&amp;nbsp; It's designed specifically to be evasive and be difficult to block.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I work for a large K-12 school district, we are obligated to take measures to ensure students are not using applications like this to circumvent web filtering.&amp;nbsp; I have a case open with Palo Alto to see if an app-id is possible but in the meantime we've managed to stop this service from functioning by blocking any "unknown-udp" traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If anyone else has run across this and has a better solution, I'm all ears.&lt;/P&gt;</description>
    <pubDate>Fri, 03 Jun 2016 16:06:50 GMT</pubDate>
    <dc:creator>brian.karleFCPS</dc:creator>
    <dc:date>2016-06-03T16:06:50Z</dc:date>
    <item>
      <title>Blocking Hexa Protocol (Hexatech VPN)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-hexa-protocol-hexatech-vpn/m-p/79079#M43140</link>
      <description>&lt;P&gt;I just became aware of this yesterday, but we were seeing a rise recently in "unknown-udp" traffic on our Palo Alto Firewalls and have discovered what it was.&amp;nbsp; The amount of traffic was significant - always used the more bandwidth than anything else on the network.&amp;nbsp; There is a new-ish VPN service by BetterNet that uses a protocol called "Hexa" (&lt;A href="https://www.betternet.co/hexatech-vpn" target="_blank"&gt;https://www.betternet.co/hexatech-vpn&lt;/A&gt;) and is free to install on Android and IOS devices.&amp;nbsp; It tunnels 100% over UDP on randomized ports to over 2300 IP addresses that we've been able to isolate.&amp;nbsp; It's designed specifically to be evasive and be difficult to block.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I work for a large K-12 school district, we are obligated to take measures to ensure students are not using applications like this to circumvent web filtering.&amp;nbsp; I have a case open with Palo Alto to see if an app-id is possible but in the meantime we've managed to stop this service from functioning by blocking any "unknown-udp" traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If anyone else has run across this and has a better solution, I'm all ears.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2016 16:06:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-hexa-protocol-hexatech-vpn/m-p/79079#M43140</guid>
      <dc:creator>brian.karleFCPS</dc:creator>
      <dc:date>2016-06-03T16:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Hexa Protocol (Hexatech VPN)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-hexa-protocol-hexatech-vpn/m-p/172417#M54391</link>
      <description>&lt;P&gt;I see this is over a year old, but it's the only "betternet" result on the community. &amp;nbsp;Did you have any luck? &amp;nbsp;Or did anyone else on here find a way and I'm just not seeing it? &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I too am in K-12 and have try my best to block this. &amp;nbsp;I'm seeing it flagged on URL filtering, but it still works, unfortunately.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2017 16:05:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-hexa-protocol-hexatech-vpn/m-p/172417#M54391</guid>
      <dc:creator>Ashley_Bell</dc:creator>
      <dc:date>2017-08-21T16:05:50Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Hexa Protocol (Hexatech VPN)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-hexa-protocol-hexatech-vpn/m-p/172424#M54392</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71440"&gt;@Ashley_Bell&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Palo Alto actually has a App-ID for this;&amp;nbsp;&lt;SPAN&gt;hexatech-vpn. I'm not sure how reliable it is but do you see that app-id within your logs at all?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2017 16:26:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-hexa-protocol-hexatech-vpn/m-p/172424#M54392</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-08-21T16:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Hexa Protocol (Hexatech VPN)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-hexa-protocol-hexatech-vpn/m-p/172434#M54400</link>
      <description>&lt;P&gt;I do, trying it out now. I appreciate the quick response!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like the app itself isn't blocked and content gets through - but the content is severely slowed, which if it makes it unusable, then good! &amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2017 17:15:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-hexa-protocol-hexatech-vpn/m-p/172434#M54400</guid>
      <dc:creator>Ashley_Bell</dc:creator>
      <dc:date>2017-08-21T17:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Hexa Protocol (Hexatech VPN)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-hexa-protocol-hexatech-vpn/m-p/172443#M54408</link>
      <description>&lt;P&gt;I was able to block it completely by blocking 'unknown-udp' and 'hexatech-vpn'.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2017 18:46:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-hexa-protocol-hexatech-vpn/m-p/172443#M54408</guid>
      <dc:creator>brian.karleFCPS</dc:creator>
      <dc:date>2017-08-21T18:46:08Z</dc:date>
    </item>
  </channel>
</rss>

