Ultrasurf Blocking Fail

Reply
Highlighted
Not applicable

Ultrasurf Blocking Fail

Hi,

I am suferring from many failed attempts trying to block ultrasurf. i added the application to a deny policy on the top of my policies, but users keeps jumping to the allow policy. i tried to block unkown UDP/TCP apps, but it failed too. the applcation itself can't be blocked even though i blocked all the dependecies. i tried to do it on 5050 and 5060 on both PAN 5.0.11 and PAN-OS 6.0 with the most updated licenses.can some one help. i guess it's considered a huge problem

L7 Applicator

Re: Ultrasurf Blocking Fail

L6 Presenter

Re: Ultrasurf Blocking Fail

There is an open case for that.It is not fixed yet.

L7 Applicator

Re: Ultrasurf Blocking Fail

Could you please update the case ID here.

Thanks

L6 Presenter

Re: Ultrasurf Blocking Fail

00171473

Thanks for help

L7 Applicator

Re: Ultrasurf Blocking Fail

Engineering is still working on this BUG. Fix is not available yet.

Thanks

Not applicable

Re: Ultrasurf Blocking Fail

the same story with kproxy and freegate !!!:smileyshocked:

L4 Transporter

Re: Ultrasurf Blocking Fail

Hi,

Does it still happen with Decryption enabled and Block sessions that cannot decrypted ? With that my own tests show it cannot get through .... Also it's useless to say unknown-tcp and unknown-udp should be blocked ...

Not applicable

Re: Ultrasurf Blocking Fail

Hi ,

the unknown-tcp and unknown-udp are blocked but should the PA block them without the need of ssl decryption policy ( i mean if we have the right signature of the application) ?!

L6 Presenter

Re: Ultrasurf Blocking Fail

with ssl decryption you will identify the real app. inside the ssl, so if you see only unknown tcp/udp , after decryption it will not change.

But if you see ssl, then it may change.

Until last version of ultrasurf, we were able to block it without decryption.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!