<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Betternet VPN Lemon VPN blocking in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/betternet-vpn-lemon-vpn-blocking/m-p/268305#M74542</link>
    <description>&lt;P&gt;Looks like a rather evasive application.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Lemon VPN allows you to unblock websites that are blocked to you by your ISP or goverment through tunnelling via different protocols like SSL, TCP, HTTP."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I would suggest the following:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Either allow only specific, sanctioned apps from the network, or make sure to block: SSH, IPSEC, the common ports used for those apps too, etc.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- A rather strict URL Filtering profile, their domain is "parked" btw.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Create a report to find which IP's are used while connecting to the tunneling services, block those IP's&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Do not allow unknown-tcp, unknown-udp traffic on the network, if necessary to allow, make sure to investigate the traffic that is required to work, create apps based on that and then go ahead to deny the unknown-tcp,udp.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jun 2019 11:19:22 GMT</pubDate>
    <dc:creator>Philip_Wiberg</dc:creator>
    <dc:date>2019-06-10T11:19:22Z</dc:date>
    <item>
      <title>Betternet VPN Lemon VPN blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/betternet-vpn-lemon-vpn-blocking/m-p/260821#M73933</link>
      <description>&lt;P&gt;Anyone know how to block these 2 apps?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Betternet VPN&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.betternet.co/" target="_blank"&gt;https://www.betternet.co/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lemon VPN&lt;/P&gt;&lt;P&gt;&lt;A href="https://play.google.com/store/apps/details?id=org.lemonvpn.android&amp;amp;hl=en_US" target="_blank"&gt;https://play.google.com/store/apps/details?id=org.lemonvpn.android&amp;amp;hl=en_US&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a BYOD at our K-12 education schools, and students are bringing their own devices in with these installed.&amp;nbsp; I assume there are other VPNs out there coming in too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have an 'open' BYOD, so no authentication needed, other than agreeing with the AUP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Palo shows no ap-id for either of these and the traffic just pokes right through.&amp;nbsp; We have proxy sites blocked via Palo URL license, and have SSL decryption enabled and make BYOD users install our ssl-forward-proxy cert if they want to use https websites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;&lt;P&gt;Dannon&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 21:14:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/betternet-vpn-lemon-vpn-blocking/m-p/260821#M73933</guid>
      <dc:creator>dannon</dc:creator>
      <dc:date>2019-05-13T21:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: Betternet VPN Lemon VPN blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/betternet-vpn-lemon-vpn-blocking/m-p/260848#M73940</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Perhaps block the ports that hey are using outbound? Typically VPN uses 500/udp. Maybe even use a application filter and use encrypted-tunnel, however this could break legit traffic so whatever you put in, I say make it an allow policy to see what else its matching.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 21:57:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/betternet-vpn-lemon-vpn-blocking/m-p/260848#M73940</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-05-13T21:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: Betternet VPN Lemon VPN blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/betternet-vpn-lemon-vpn-blocking/m-p/268305#M74542</link>
      <description>&lt;P&gt;Looks like a rather evasive application.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Lemon VPN allows you to unblock websites that are blocked to you by your ISP or goverment through tunnelling via different protocols like SSL, TCP, HTTP."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I would suggest the following:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Either allow only specific, sanctioned apps from the network, or make sure to block: SSH, IPSEC, the common ports used for those apps too, etc.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- A rather strict URL Filtering profile, their domain is "parked" btw.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Create a report to find which IP's are used while connecting to the tunneling services, block those IP's&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Do not allow unknown-tcp, unknown-udp traffic on the network, if necessary to allow, make sure to investigate the traffic that is required to work, create apps based on that and then go ahead to deny the unknown-tcp,udp.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2019 11:19:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/betternet-vpn-lemon-vpn-blocking/m-p/268305#M74542</guid>
      <dc:creator>Philip_Wiberg</dc:creator>
      <dc:date>2019-06-10T11:19:22Z</dc:date>
    </item>
    <item>
      <title>Re: Betternet VPN Lemon VPN blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/betternet-vpn-lemon-vpn-blocking/m-p/268344#M74545</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Looks like a URL filter policy might be able to help as well. But I agree the kids will try to find a way around stuff. Have daily reports and review the traffic to see what new stuff they are trying any make sure its getting blocked. I'm sure a lot of others would love to see how you are blocking these attempts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2019 13:10:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/betternet-vpn-lemon-vpn-blocking/m-p/268344#M74545</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-06-10T13:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: Betternet VPN Lemon VPN blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/betternet-vpn-lemon-vpn-blocking/m-p/343859#M86054</link>
      <description>&lt;P&gt;Greetings from a K-12 private school in &lt;SPAN class="st"&gt;Wisconsin&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;I'm a school psychologist and very often I ask students to watch videos and lectures on the reliable educational web resources, but they go further than that - they start looking for other stuff, sometimes, it concerns violent scenes and bullying. They are trying to bypass our security measures all the time. What is a sure fire way to block Proxy and VPN tools for good?&lt;/P&gt;&lt;P&gt;Should I perform whitelisting?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Dani&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;FONT size="2"&gt;Dani Dapo (Omoiyadapo)&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Access support: &lt;A href="https://live.paloaltonetworks.com/t5/general-topics/how-can-i-detect-and-stop-3rd-party-vpn-tools-used-to-bypass-my/td-p/33550" target="_self"&gt;&lt;FONT color="#333333"&gt;https://live.paloaltonetworks.com/t5/general-topics/how-can-i-stop-vpn-tools-used-to-bypass&lt;/FONT&gt;&lt;/A&gt; &lt;A href="https://essaytyper.pro/" target="_self"&gt;&lt;FONT color="#333333"&gt;essaytyper.pro&lt;/FONT&gt;&lt;/A&gt; &lt;FONT color="#FFFFFF"&gt;paper generator&lt;/FONT&gt;&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2020 04:46:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/betternet-vpn-lemon-vpn-blocking/m-p/343859#M86054</guid>
      <dc:creator>Omoiyadapo</dc:creator>
      <dc:date>2020-08-14T04:46:10Z</dc:date>
    </item>
    <item>
      <title>Re: Betternet VPN Lemon VPN blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/betternet-vpn-lemon-vpn-blocking/m-p/343983#M86076</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/152114"&gt;@Omoiyadapo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;There is no sure fire way to block proxies and VPN solutions across the board, and while a robust whitelisting process can help limit the issue it'll never completely rid the issue. New Proxies and VPN solutions come online all the time, and smart students can spin up their own on any port that you leave open.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can create an extremely limited rulebase which only allows access to "approved" resources, but in a school environment that would be extremely time consuming. Students will find a way to get around things unless you completely restrict access.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Aug 2020 03:30:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/betternet-vpn-lemon-vpn-blocking/m-p/343983#M86076</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-08-15T03:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: Betternet VPN Lemon VPN blocking</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/betternet-vpn-lemon-vpn-blocking/m-p/344249#M86132</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;This maybe a case of always being behind the ball. As stated before, Configure your URL filtering as well as the other security policies and objects. Then have the firewall generate reports as to the websites that are getting hit. Review the logs daily and see if you can see a pattern. Also SSL decryption can be a benefit here since the PAN can possibly determine the application and if you have it blocked. Make sure you are sending PAN your telemetry so their algorithms can reprocess and dynamically update their feeds. This not only helps you but everyone attempt's to do the same thing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let us know which way you go so the rest of the community can follow the leader and do something similar :).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 21:27:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/betternet-vpn-lemon-vpn-blocking/m-p/344249#M86132</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-08-17T21:27:52Z</dc:date>
    </item>
  </channel>
</rss>

