Ultrasurf Blocking Fail

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

Ultrasurf Blocking Fail

Not applicable


I am suferring from many failed attempts trying to block ultrasurf. i added the application to a deny policy on the top of my policies, but users keeps jumping to the allow policy. i tried to block unkown UDP/TCP apps, but it failed too. the applcation itself can't be blocked even though i blocked all the dependecies. i tried to do it on 5050 and 5060 on both PAN 5.0.11 and PAN-OS 6.0 with the most updated licenses.can some one help. i guess it's considered a huge problem


L7 Applicator

L6 Presenter

There is an open case for that.It is not fixed yet.

Could you please update the case ID here.



Thanks for help

Engineering is still working on this BUG. Fix is not available yet.


Not applicable

the same story with kproxy and freegate !!!:smileyshocked:


Does it still happen with Decryption enabled and Block sessions that cannot decrypted ? With that my own tests show it cannot get through .... Also it's useless to say unknown-tcp and unknown-udp should be blocked ...

Hi ,

the unknown-tcp and unknown-udp are blocked but should the PA block them without the need of ssl decryption policy ( i mean if we have the right signature of the application) ?!

with ssl decryption you will identify the real app. inside the ssl, so if you see only unknown tcp/udp , after decryption it will not change.

But if you see ssl, then it may change.

Until last version of ultrasurf, we were able to block it without decryption.

I believe you have already opened a case but incase you have not i would recommend opening a case with support with the following information

1. Application version of Ultrasurf

2. pcap of the traffic from the client side

3. traffic logs during your testing

4. techsupport file

Hope this helps.



This is not wokring with last version

even using a decryption profile, ultrasurf works.

I have followed on the issue. This currently being investigated by engineering team.

Thank you


L2 Linker

It seems ultrasurf has updated it's proxy network. based from the current version 13.04, PAN detects Ultrasurf and denies it. however it passes thru for some weird reasons and now the software calls for HE.NET which resides in the USA. i have responded to an older query regarding Ultrasurf but during that time, the software calls / connect to Taiwan (HINET) which i stated to block the whole country to prevent ultrasurf from connecting. What you can do for now is to double check your filters and make sure ultrasurf and unknown-tcp are on your app block-list. This may not be full proof but it can slow "ultrasurf" to a crawl (for the mean time). which i'm doing right now. Let's hope PAN team can resolve this quickly.


Same problem with TOR.


  • 30 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!