Screen OS

last person joined: 8 months ago 

This is a legacy community with limited Juniper monitoring.
  • 1.  How to block bypassing program like zenmate..

    Posted 08-24-2015 19:40

    Hi all,

    As you can see the title, we wondered how to block bypassing program like zenmate.

    We've set up the network as below photo.

    The setting we did is just blocking specific URL.

     

    However, we got a problem.

    That's because our customers bypass specific URL we've blocked using the zenmate.

     

    So, I want to get a solution how to block bypassing program...

     

    rf) I heard that we do not block bypassing program.

    Even though we block this program, maybe it is not a good solution because is there another method.

    Hmmm do you agree these opinion? ( http://security.stackexchange.com/questions/97206/how-to-block-detour-programs-that-bypass-firewalls )

    Network construction_plan.JPEGtt



  • 2.  RE: How to block bypassing program like zenmate..
    Best Answer

     
    Posted 08-25-2015 01:30

    Hi,

     

    Blocking bypaaers, tunnel programs. proxies etc., is difficult on a firewall level.

     

    If the program uses SSL tunnels, you can try blocking zenmate.anything completely. But, users will come up with a new program to continue bypassing the system and fly under the RADAR.

     

    A better approach is to control this on user machines, by implementing corporate access policies, program restrictions etc.,


    #firewall


  • 3.  RE: How to block bypassing program like zenmate..

    Posted 08-25-2015 01:56

    Thank you sir...

    I think Firewall does support bypassing program.

    Hmm...

    It is very hard to block it..

     

    Thank you sir.

    Regards,



  • 4.  RE: How to block bypassing program like zenmate..

     
    Posted 08-25-2015 02:19

    Just to add to what Gokul has said:

     

    Zenmate sends initial requests to following server:

     

    zenguard.biz
    zenguard.org
    zenmate.io

     

    So you can try to put them in URL blacklist.

     

    However this is not a complete solution. Ideal solution would be to have control on which extensions, softwares end user can download & use.

     

    Thanks & Regards,

     

    Rushi



  • 5.  RE: How to block bypassing program like zenmate..

    Posted 08-25-2015 18:09

    It's kind of you.

    I'll give it a try!!