02-23-2014 08:38 AM
I am suferring from many failed attempts trying to block ultrasurf. i added the application to a deny policy on the top of my policies, but users keeps jumping to the allow policy. i tried to block unkown UDP/TCP apps, but it failed too. the applcation itself can't be blocked even though i blocked all the dependecies. i tried to do it on 5050 and 5060 on both PAN 5.0.11 and PAN-OS 6.0 with the most updated licenses.can some one help. i guess it's considered a huge problem
02-23-2014 10:27 AM
Few related discussions, it might help you:
Re: Ultrasurf 13.03 appearing as unknown-tcp
Re: unknown-tcp / udp - please explain
02-24-2014 01:34 AM
Could you please update the case ID here.
02-24-2014 01:37 AM
02-24-2014 02:25 AM
Engineering is still working on this BUG. Fix is not available yet.
02-24-2014 03:26 AM
the same story with kproxy and freegate !!!:smileyshocked:
02-24-2014 08:53 AM
Does it still happen with Decryption enabled and Block sessions that cannot decrypted ? With that my own tests show it cannot get through .... Also it's useless to say unknown-tcp and unknown-udp should be blocked ...
02-26-2014 12:23 PM
the unknown-tcp and unknown-udp are blocked but should the PA block them without the need of ssl decryption policy ( i mean if we have the right signature of the application) ?!
02-26-2014 12:56 PM
with ssl decryption you will identify the real app. inside the ssl, so if you see only unknown tcp/udp , after decryption it will not change.
But if you see ssl, then it may change.
Until last version of ultrasurf, we were able to block it without decryption.
02-26-2014 12:57 PM
I believe you have already opened a case but incase you have not i would recommend opening a case with support with the following information
1. Application version of Ultrasurf
2. pcap of the traffic from the client side
3. traffic logs during your testing
4. techsupport file
Hope this helps.
02-27-2014 12:01 AM
This is not wokring with last version
even using a decryption profile, ultrasurf works.
02-27-2014 10:31 AM
I have followed on the issue. This currently being investigated by engineering team.
03-04-2014 01:56 AM
It seems ultrasurf has updated it's proxy network. based from the current version 13.04, PAN detects Ultrasurf and denies it. however it passes thru for some weird reasons and now the software calls for HE.NET which resides in the USA. i have responded to an older query regarding Ultrasurf but during that time, the software calls / connect to Taiwan (HINET) which i stated to block the whole country to prevent ultrasurf from connecting. What you can do for now is to double check your filters and make sure ultrasurf and unknown-tcp are on your app block-list. This may not be full proof but it can slow "ultrasurf" to a crawl (for the mean time). which i'm doing right now. Let's hope PAN team can resolve this quickly.
03-04-2014 02:45 AM
Same problem with TOR.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!