Bypass Firewall and block Download Accelerator

Reply
Highlighted
L1 Bithead

Bypass Firewall and block Download Accelerator

https://wordpress.com/post/nbctcp.wordpress.com/1811

 

I want to know whether PANOS 9.x be able to block some technique to bypass firewall and download accelerator such as

1. DNS over TLS (method 11)

2. Soft Ether (method 7)

3. ZenMate (method 3)

4. Opera Turbo (method 2)

5. Open Proxy (method 5)

6. IDM (method

7. FDM (method 9)

8. IDA (method 10)

 

tq

L7 Applicator

Re: Bypass Firewall and block Download Accelerator

Hello,

You might be able to block some of this traffic with App-ID and URL filtering. As for the DNS, we block all DNS outbound traffic except from our internal DNS servers.

 

Regards,

L1 Bithead

Re: Bypass Firewall and block Download Accelerator

How if DNS over HTTPS or TLS. or SSH

L2 Linker

Re: Bypass Firewall and block Download Accelerator

By definition, unless you decrypt outbound traffic, no firewall would be able to tell DNS over HTTPs traffic from the rest, especially if DoH is implemented over a large cloud infrastructure that you can't block with IP lists (think about Cloudflare and Google, which might host the service on their "base image" and mix up services at their will).

I think the only currently viable solution is browser makers honoring some "kill switch" mechanism (e.g. Mozilla's canary domain: https://support.mozilla.org/en-US/kb/canary-domain-use-application-dnsnet and network administrators implementing it, where appropriate (I'm thinking about networks where you have a split-DNS situation, and external clients are pointed to a different IP than internal ones... ...lots of reasons to do this, and not all of them can be worked around). Anyway, not really a firewall problem/solution, here, unless we start fiddling with PAN's DNS proxy.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!