Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Unable to block VPN apps?

    Scheduled Pinned Locked Moved Firewalling
    9 Posts 6 Posters 683 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dxplorer11
      last edited by

      I noticed that If any smartphone use VPN apps, it bypasses any firewall rules and all dns settings set by the pfsense router. Ive forced all the clients in my LAN to use the PfSense DNS settings that are actually pointing to my windows server dns, but if they use a vpn app on their devices, it completely bypasses the router.

      viktor_gV 1 Reply Last reply Reply Quote 0
      • RicoR
        Rico LAYER 8 Rebel Alliance
        last edited by

        You can try to block VPN providers with pfBlockerNG.

        -Rico

        D Sergei_ShablovskyS 2 Replies Last reply Reply Quote 1
        • D
          dxplorer11 @Rico
          last edited by

          @rico Lets assume that we dont know the vpn providers name they are using.

          KOMK 1 Reply Last reply Reply Quote 0
          • KOMK
            KOM @dxplorer11
            last edited by KOM

            @dxplorer11 Then you're limited to blocking based on destination address or port. Since the contents of each packet is encrypted, all you have to work with are the tcp/udp headers.

            1 Reply Last reply Reply Quote 1
            • viktor_gV
              viktor_g Netgate @dxplorer11
              last edited by

              @dxplorer11 said in Unable to block VPN apps?:

              I noticed that If any smartphone use VPN apps, it bypasses any firewall rules and all dns settings set by the pfsense router. Ive forced all the clients in my LAN to use the PfSense DNS settings that are actually pointing to my windows server dns, but if they use a vpn app on their devices, it completely bypasses the router.

              You could try to block VPN with Snort/Suricata or pfBlockerNG IP VPN feed

              JeGrJ Sergei_ShablovskyS 2 Replies Last reply Reply Quote 1
              • JeGrJ
                JeGr LAYER 8 Moderator @viktor_g
                last edited by

                Blocking IPsec would be pretty easy but OVPN and WG can run on whatever port, so only way would be to rely on IP lists and perhaps ASNs of public VPN providers. You don't get them all but if you get many/most of the VPN endpoints the client tries to connect to, then at least it wouldn't be easy to circumvent the rules.

                Easiest thing would be to move smartphones to a separate VLAN and also limit access to certain ports and services in addition to then block certain IP ranges and DNS aliases so many/most VPNs wouldn't connect.

                Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

                If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

                Sergei_ShablovskyS 1 Reply Last reply Reply Quote 1
                • Sergei_ShablovskyS
                  Sergei_Shablovsky @Rico
                  last edited by Sergei_Shablovsky

                  @rico said in Unable to block VPN apps?:

                  You can try to block VPN providers with pfBlockerNG.

                  -Rico

                  Good suggestion for authority and anti-democratic regimes like in Russia, Belorussia, China, Iran, Sirya... ;)

                  —
                  CLOSE SKY FOR UKRAINE https://youtu.be/_tU1i8VAdCo !
                  Help Ukraine to resist, save civilians people’s lives !
                  (Take an active part in public protests, push on Your country’s politics, congressmans, mass media, leaders of opinion.)

                  1 Reply Last reply Reply Quote 0
                  • Sergei_ShablovskyS
                    Sergei_Shablovsky @JeGr
                    last edited by Sergei_Shablovsky

                    @jegr said in Unable to block VPN apps?:

                    Blocking IPsec would be pretty easy but OVPN and WG can run on whatever port, so only way would be to rely on IP lists and perhaps ASNs of public VPN providers. You don't get them all but if you get many/most of the VPN endpoints the client tries to connect to, then at least it wouldn't be easy to circumvent the rules.

                    An in addition to that new technologies like NewNode VPN also make VPN blocking impossible nowadays.

                    Easiest thing would be to move smartphones to a separate VLAN and also limit access to certain ports and services in addition to then block certain IP ranges and DNS aliases so many/most VPNs wouldn't connect.

                    Totally agree.

                    —
                    CLOSE SKY FOR UKRAINE https://youtu.be/_tU1i8VAdCo !
                    Help Ukraine to resist, save civilians people’s lives !
                    (Take an active part in public protests, push on Your country’s politics, congressmans, mass media, leaders of opinion.)

                    1 Reply Last reply Reply Quote 0
                    • Sergei_ShablovskyS
                      Sergei_Shablovsky @viktor_g
                      last edited by

                      @viktor_g said in Unable to block VPN apps?:

                      @dxplorer11 said in Unable to block VPN apps?:

                      I noticed that If any smartphone use VPN apps, it bypasses any firewall rules and all dns settings set by the pfsense router. Ive forced all the clients in my LAN to use the PfSense DNS settings that are actually pointing to my windows server dns, but if they use a vpn app on their devices, it completely bypasses the router.

                      You could try to block VPN with Snort/Suricata or pfBlockerNG IP VPN feed

                      If users using NewNode VPN, both methods not a solution.

                      Slowly we all goes to stay when blocking VPNs become impossible, because slowly all connections become to “VPN by design”. And billions of investments just push all industry forward to this stay.

                      —
                      CLOSE SKY FOR UKRAINE https://youtu.be/_tU1i8VAdCo !
                      Help Ukraine to resist, save civilians people’s lives !
                      (Take an active part in public protests, push on Your country’s politics, congressmans, mass media, leaders of opinion.)

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.