Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to Block free gate proxy application

    Scheduled Pinned Locked Moved General pfSense Questions
    10 Posts 4 Posters 6.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      deepakaagrwal
      last edited by

      Hiiiiiiii  I am new in this forum, it would be appreciated if some one help to block free gate proxy software in pfsense so that clients can not bypass it.
      Thanks in advance

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        You have a link to that software?
        It can be very difficult to block these types of applications because they are specifically designed to get around blocks!

        Steve

        1 Reply Last reply Reply Quote 0
        • D
          deepakaagrwal
          last edited by

          Can we do this through firewall rules by blocking ports

          1 Reply Last reply Reply Quote 0
          • M
            mendilli
            last edited by

            if I was an expert on firewalling I would say "block everything at the first place, then only allow what you use"

            1 Reply Last reply Reply Quote 0
            • D
              deepakaagrwal
              last edited by

              Dear All

              how to block traffic of proxies software just like freegate, tor, hotspotshield, ultrasutf and many more , can we dont block through single rule by allowing only trusted traffic. Some users also use chrome or firefox extenstions like hola to bypass pfsense box can we dont block it.

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                Yes do that^. However it probably won't block the proxy program because they usually use common ports which you will have to allow for exactly this reason, say 443 or 53.
                We need more info on the exact program you're asking about.

                Steve

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  Ah, OK.
                  So ultrasurf in particular is difficult to block.
                  I have never tried to do it but there have been several threads on the forum discussing blocking methods and also several good articles on blogs I've read.

                  Steve

                  1 Reply Last reply Reply Quote 0
                  • D
                    deepakaagrwal
                    last edited by

                    OK I m waiting for your valuable reply so that i can make my pfsense box most effective.

                    1 Reply Last reply Reply Quote 0
                    • N
                      Nachtfalke
                      last edited by

                      Hi,

                      it is the same as with teamviewer. The possibilities you have are:

                      • Only allow ports you need and block everything else

                      • Use a proxy like squid and a filter like squidguard or dansguardian and block the domains for this programs you would like to block and disallow bypassing by plain IP address.

                      • If it cannot be blocked by port because the applications use common ports like 443 and you need this for your other users then create an host alias and put in the domains and subdomains these applications connect to. Then add these aliases into a block rule as destination IP on your firewall rules

                      You probably need to log all traffic and connections when using the specific program to log which ports and destination IPs this program uses. Then block it and try again. Many programs use different ports and IP addresses if one isn't reachable.

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        Using Snort with a specific signature for Ultrasurf seems like a better way to do it. Maybe using Layer7 with a specific pattern. Although even using these will fail eventually as ultrasurf employs many techniques to disguise itself.
                        If you look at firewalls that claim to able to block it (Watchguard, Sonicwall) they are doing it using Layer7 pattern recognition.

                        You can attempt to block the IPs ultrasurf uses for it's servers but it will fail eventually as the list is a constantly moving target.

                        Steve

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.