• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How to Block free gate proxy application

Scheduled Pinned Locked Moved General pfSense Questions
10 Posts 4 Posters 6.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    deepakaagrwal
    last edited by Nov 28, 2013, 7:10 AM

    Hiiiiiiii  I am new in this forum, it would be appreciated if some one help to block free gate proxy software in pfsense so that clients can not bypass it.
    Thanks in advance

    1 Reply Last reply Reply Quote 0
    • S
      stephenw10 Netgate Administrator
      last edited by Nov 28, 2013, 7:10 PM

      You have a link to that software?
      It can be very difficult to block these types of applications because they are specifically designed to get around blocks!

      Steve

      1 Reply Last reply Reply Quote 0
      • D
        deepakaagrwal
        last edited by Nov 29, 2013, 11:23 AM

        Can we do this through firewall rules by blocking ports

        1 Reply Last reply Reply Quote 0
        • M
          mendilli
          last edited by Nov 29, 2013, 2:14 PM

          if I was an expert on firewalling I would say "block everything at the first place, then only allow what you use"

          1 Reply Last reply Reply Quote 0
          • D
            deepakaagrwal
            last edited by Nov 29, 2013, 4:54 PM

            Dear All

            how to block traffic of proxies software just like freegate, tor, hotspotshield, ultrasutf and many more , can we dont block through single rule by allowing only trusted traffic. Some users also use chrome or firefox extenstions like hola to bypass pfsense box can we dont block it.

            1 Reply Last reply Reply Quote 0
            • S
              stephenw10 Netgate Administrator
              last edited by Nov 29, 2013, 4:56 PM

              Yes do that^. However it probably won't block the proxy program because they usually use common ports which you will have to allow for exactly this reason, say 443 or 53.
              We need more info on the exact program you're asking about.

              Steve

              1 Reply Last reply Reply Quote 0
              • S
                stephenw10 Netgate Administrator
                last edited by Nov 29, 2013, 5:05 PM

                Ah, OK.
                So ultrasurf in particular is difficult to block.
                I have never tried to do it but there have been several threads on the forum discussing blocking methods and also several good articles on blogs I've read.

                Steve

                1 Reply Last reply Reply Quote 0
                • D
                  deepakaagrwal
                  last edited by Nov 30, 2013, 2:17 AM

                  OK I m waiting for your valuable reply so that i can make my pfsense box most effective.

                  1 Reply Last reply Reply Quote 0
                  • N
                    Nachtfalke
                    last edited by Nov 30, 2013, 1:38 PM

                    Hi,

                    it is the same as with teamviewer. The possibilities you have are:

                    • Only allow ports you need and block everything else

                    • Use a proxy like squid and a filter like squidguard or dansguardian and block the domains for this programs you would like to block and disallow bypassing by plain IP address.

                    • If it cannot be blocked by port because the applications use common ports like 443 and you need this for your other users then create an host alias and put in the domains and subdomains these applications connect to. Then add these aliases into a block rule as destination IP on your firewall rules

                    You probably need to log all traffic and connections when using the specific program to log which ports and destination IPs this program uses. Then block it and try again. Many programs use different ports and IP addresses if one isn't reachable.

                    1 Reply Last reply Reply Quote 0
                    • S
                      stephenw10 Netgate Administrator
                      last edited by Nov 30, 2013, 2:26 PM

                      Using Snort with a specific signature for Ultrasurf seems like a better way to do it. Maybe using Layer7 with a specific pattern. Although even using these will fail eventually as ultrasurf employs many techniques to disguise itself.
                      If you look at firewalls that claim to able to block it (Watchguard, Sonicwall) they are doing it using Layer7 pattern recognition.

                      You can attempt to block the IPs ultrasurf uses for it's servers but it will fail eventually as the list is a constantly moving target.

                      Steve

                      1 Reply Last reply Reply Quote 0
                      1 out of 10
                      • First post
                        1/10
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        This community forum collects and processes your personal information.
                        consent.not_received