<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Psiphon blocking in a non-decrypted network in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/psiphon-blocking-in-a-non-decrypted-network/m-p/436629#M96288</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/159497"&gt;@MRamadanAHafiez&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If you can't enable decryption and you can't block the associated app-ids that the traffic relies on, the next possible step would be blocking the domains or hosts that Psiphon relies on. Due to how Psiphon works and how it connects, you&amp;nbsp;&lt;STRONG&gt;can't&amp;nbsp;&lt;/STRONG&gt;really successfully block it without Decryption enabled.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this is something you simply can't enable on your network I would start blocking clients you've identified as running this traffic. Assuming you have rules against bypassing your firewall, simply block anyone you've identified as bypassing the firewall.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 26 Sep 2021 03:16:39 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2021-09-26T03:16:39Z</dc:date>
    <item>
      <title>Psiphon blocking in a non-decrypted network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/psiphon-blocking-in-a-non-decrypted-network/m-p/436573#M96277</link>
      <description>&lt;P&gt;Hello Bros'&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Recently, I have issues with the application called Psiphon, this app is eating my internet based on authentication portal page.&lt;/P&gt;&lt;P&gt;As I check previous threads in the community, all speaking about a decrypted traffic or blocking an applications that are vital such as&amp;nbsp;http-proxy&lt;BR /&gt;,ike, ipsec, l2tp, ssh,&amp;nbsp;ssh-tunnel.&lt;/P&gt;&lt;P&gt;it a virtual wire deployment and traffic decryption can't be done due to network needs.&lt;/P&gt;&lt;P&gt;Any one who could succeed in this Psiphon blocking because simply blocking the application in a security rule is not working unless traffic being decrypted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any recommendation, Thanx in advance.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Sep 2021 14:06:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/psiphon-blocking-in-a-non-decrypted-network/m-p/436573#M96277</guid>
      <dc:creator>MRamadanAHafiez</dc:creator>
      <dc:date>2021-09-25T14:06:27Z</dc:date>
    </item>
    <item>
      <title>Re: Psiphon blocking in a non-decrypted network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/psiphon-blocking-in-a-non-decrypted-network/m-p/436629#M96288</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/159497"&gt;@MRamadanAHafiez&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If you can't enable decryption and you can't block the associated app-ids that the traffic relies on, the next possible step would be blocking the domains or hosts that Psiphon relies on. Due to how Psiphon works and how it connects, you&amp;nbsp;&lt;STRONG&gt;can't&amp;nbsp;&lt;/STRONG&gt;really successfully block it without Decryption enabled.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this is something you simply can't enable on your network I would start blocking clients you've identified as running this traffic. Assuming you have rules against bypassing your firewall, simply block anyone you've identified as bypassing the firewall.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Sep 2021 03:16:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/psiphon-blocking-in-a-non-decrypted-network/m-p/436629#M96288</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-09-26T03:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: Psiphon blocking in a non-decrypted network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/psiphon-blocking-in-a-non-decrypted-network/m-p/437109#M97391</link>
      <description>&lt;P&gt;i had that same issue but with users personal mobile phones, i made a dynamic group and auto tagged and blocked the users that used psiphone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as you will see that psiphone tries to connect with ssh as well and changes the sites SNI field to random sites to hide the URL traffic&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 08:04:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/psiphon-blocking-in-a-non-decrypted-network/m-p/437109#M97391</guid>
      <dc:creator>LAS</dc:creator>
      <dc:date>2021-09-28T08:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: Psiphon blocking in a non-decrypted network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/psiphon-blocking-in-a-non-decrypted-network/m-p/439852#M99847</link>
      <description>&lt;P&gt;Thank for you add LAS.&lt;/P&gt;&lt;P&gt;I have exactly same issue with mobile phone but the psiohon changes alot, hence blocking it won't work.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Oct 2021 19:39:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/psiphon-blocking-in-a-non-decrypted-network/m-p/439852#M99847</guid>
      <dc:creator>MRamadanAHafiez</dc:creator>
      <dc:date>2021-10-09T19:39:34Z</dc:date>
    </item>
  </channel>
</rss>

