• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How to block proxy software like Hidemyass

Firewalling
4
9
2.7k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C
    catey03
    last edited by Dec 4, 2014, 5:29 PM

    Hello guys,

    What is the most effective way to block proxy softwares like hidemyass so that nobody can bypass our firewall rules? I have squiduard installed and also using OpenDNS IP's but still I'm unable to block it. Please advice. Thank you!

    1 Reply Last reply Reply Quote 0
    • K
      KOM
      last edited by Dec 4, 2014, 6:14 PM

      Get a master list of all the IP addresses for the service that you want to block.  Create an alias and load it with those IP addresses.  Block access via firewall to a destination represented by the alias.  This is the whack-a-mole method and is not that great.  If the user is using VPN software that uses particular source or destination ports then you can block based on that.  Squidguard has a blacklist category for Anonvpn, but I have no idea what's in that category.

      1 Reply Last reply Reply Quote 0
      • D
        Derelict LAYER 8 Netgate
        last edited by Dec 4, 2014, 6:58 PM

        Tell them not to and if they continue, fire them.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • C
          catey03
          last edited by Dec 4, 2014, 7:26 PM

          @KOM thanks for the advice..But what if they use other proxy software? I think that won't work..I have already denied access to squidguard Anonvpn blacklist category but still no luck.

          @Derelict That's a good idea. lol ;D

          1 Reply Last reply Reply Quote 0
          • K
            KOM
            last edited by Dec 4, 2014, 8:06 PM

            Like I said, there is no magic solution when it comes to blocking moving targets.  At the end of the day, all you can do is block access to particular IP addresses.  That's it.  It's up to you to figure out what those IP addresses might be.  There is no one "block every commercial VPN and every IP address they use in the whole world' list that I'm aware of, and if there was such a thing it would probably have a subscription fee.  What if your user has a VPS and is hosting his own OpenVPN or IPSEC instance?

            1 Reply Last reply Reply Quote 0
            • C
              catey03
              last edited by Dec 4, 2014, 8:22 PM

              Is there a feature in pfSense when a user use a proxy software it alerts the admin? So I can disconnect them from the network?

              1 Reply Last reply Reply Quote 0
              • K
                KOM
                last edited by Dec 4, 2014, 8:33 PM

                Nope.  How would it know?

                1 Reply Last reply Reply Quote 0
                • C
                  catey03
                  last edited by Dec 4, 2014, 8:52 PM

                  Not sure how.. :)

                  Any ideas pfSense users?

                  1 Reply Last reply Reply Quote 0
                  • H
                    Harvy66
                    last edited by Dec 4, 2014, 11:11 PM

                    If the traffic is encrypted and you don't know what IPs or ports to block, then logically there is nothing you can do. The only way to even have a chance is to create a whitelist and only allow access to certain IP addresses.

                    1 Reply Last reply Reply Quote 0
                    6 out of 9
                    • First post
                      6/9
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.