Psiphon application

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

Psiphon application

L4 Transporter

Hello All,

I have configured to block streaming-media and online-storage-and-backup category by URL filtering profile.

 

Issue:- Users will connect to the Psiphon application and can access the blocking website.

I tried the below option:-

- Apply SSL forward proxy decryption with decryption profile to check block session with unsupported cipher suites.
- I have gone through the below KB and tried to block the Psiphon but couldn't

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClU2CAK

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClDzCAK

 

Below is the screen-shot before connecting the Psiphon application and it is expected.:-

 

 

Jafar_Hussain_0-1620028382551.png

 

 

Below is the screenshot after connecting the Psiphon application.

 

Jafar_Hussain_1-1620028553107.png

 

Jafar_Hussain_2-1620028579058.png

 

has anyone had an idea how I can block this?

 

7 REPLIES 7

L3 Networker

Try below steps :

1. Block unknow category in url filtering profile

2. Do not bypass any pre-defined url category in decryption bypass.

3. In decryption rule select service any.

After applying this steps  Psiphon is connecting only few seconds (20sec -30 sec) , and after that its disconnecting automatically.

 

Cyber Elite
Cyber Elite

@Jafar_Hussain,

Create a policy that includes consequences for accessing blocked resources, and then have management backing to enforce those consequences. That's the only way you're ever going to stop people finding new ways to bypass your efforts, and you'll never be able to fully prevent someone from doing so. 

 

thanks

L4 Transporter

@Deepak_K @tuteng @BPry 

 

Tried with the option provided by Deepak, but still, the issue is the same.

 

In addition to all of the above, put and monitor Psiphon traffic to external and you will find that it every time it tries to connecting, it visits many sites that make his connection and to his server as a tunnel connection to bypass the traffic.

 

Try to block these sites because they are not in the blocked category of sites, but note that there are very many of them.

L0 Member

Hello everyone,

 

Has anyone succeeded in blocking this app recently?

There is an existing "psiphon" Application ID with a risk score of 5 (not sure when it was added). Presumably you could identify the traffic by application and drop/reset it automatically in a rule once detected. We have an explicit drop rule for all applications with a risk score of 5.

  • 4105 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!