<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prevent User Traffic from Proton VPN Application in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-user-traffic-from-proton-vpn-application/m-p/350012#M86920</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155233"&gt;@DWilkin&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How is the traffic being identified ? Are you decrypting (if possible) ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could try blocking encrypted tunnel and proxy traffic.&amp;nbsp; But you might be blocking too much this way.&lt;/P&gt;
&lt;P&gt;In addition you can block IP addresses that the app is using.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Thu, 17 Sep 2020 09:57:45 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2020-09-17T09:57:45Z</dc:date>
    <item>
      <title>Prevent User Traffic from Proton VPN Application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-user-traffic-from-proton-vpn-application/m-p/348474#M86742</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just wondering if anyone has a solution in creating either an application id for proton vpn, and or other methods in preventing users from bypassing the palo firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://protonvpn.com/" target="_blank"&gt;https://protonvpn.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have discovered today that this application is not being blocked or denied access from internal users.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 08:01:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-user-traffic-from-proton-vpn-application/m-p/348474#M86742</guid>
      <dc:creator>DWilkin</dc:creator>
      <dc:date>2020-09-11T08:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent User Traffic from Proton VPN Application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-user-traffic-from-proton-vpn-application/m-p/350012#M86920</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/155233"&gt;@DWilkin&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How is the traffic being identified ? Are you decrypting (if possible) ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could try blocking encrypted tunnel and proxy traffic.&amp;nbsp; But you might be blocking too much this way.&lt;/P&gt;
&lt;P&gt;In addition you can block IP addresses that the app is using.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 17 Sep 2020 09:57:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-user-traffic-from-proton-vpn-application/m-p/350012#M86920</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-09-17T09:57:45Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent User Traffic from Proton VPN Application</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-user-traffic-from-proton-vpn-application/m-p/350257#M86947</link>
      <description>&lt;P&gt;Hi Kiwi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Doing some deeper log searchers it appears that open-vpn is capturing and recording users use of proton vpn application. Currently checking and creating restrictions on the app-id open vpn for these group of users. Will advise once I have had time to perform some testing.&lt;/P&gt;&lt;P&gt;Appreciate your response and input though - cheers.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 00:01:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-user-traffic-from-proton-vpn-application/m-p/350257#M86947</guid>
      <dc:creator>DWilkin</dc:creator>
      <dc:date>2020-09-18T00:01:56Z</dc:date>
    </item>
  </channel>
</rss>

