Student extensive use of VPNs.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Student extensive use of VPNs.

L1 Bithead

Hello Livecommunity. We are in a bind. We have numerous students on our school networks that are bypassing security profile rules with VPNs. So frustrating. I do have rulesets that look for annnomizers and proxies. I also have explicit rules that look for categories such as Facebook, Snapchat, etc... Not sure what to do. I worry that the more rules I setup in the firewall, the more work it has to do and gets sluggish? Am I right? I did see something about disabling 'QUIC" which I can but want this firewall to be optimized and working very well. 

 

Any suggestions (even mean ones) appreciated. 

 

Best,

 

Jean-Claude

4 REPLIES 4

Cyber Elite
Cyber Elite

Firewall don't see into QUIC traffic so it is best practice to block it.

Block URL category proxy-avoidance-and-anonymizers

 

In addition create application filter for subcategory "encrypted-tunnel" (Objects > Application Filters) and block it for students.

Place this block rule after you have permitted outgoing SSL application.

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Thanks @Radio_Rattameister, will try tonight. 

 

 

L0 Member

I hope you found a solution to the problem.

L2 Linker

Hi,

 

so if the users are applying VPN's why dont you create a rule for lets say 'zone class B' that is not allow to do traffic the traffic that you saw?
do the rule based on layer 4 tcp/udp port number

  • 4623 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!