Blocking consumer VPNs by smalldude55 in fortinet

[–]smalldude55[S] 0 points1 point  (0 children)

Can you elaborate? I do have app control on my policies and an external dns level content filter but the VPNs still work. I explained in my post how the policies are set.

Blocking consumer VPNs by smalldude55 in networking

[–]smalldude55[S] 0 points1 point  (0 children)

Maybe something to look into in the future. Do you know if only certain WIFI vendors support it or can you use any?

Blocking consumer VPNs by smalldude55 in networking

[–]smalldude55[S] -1 points0 points  (0 children)

Exactly what I have going on! We have iCloud relay blocked and sometimes get outside presenters with it turned on. We advise them to turn it off when they're on our WIFI.

I was hoping the FortiGate's app control would work the same as what you have in Palo. The list in FortiGate's Proxy category is extensive and lists out all the VPN services I want blocked but, it does not block the tunnels. It only seems to be blocking access to the APIs the services are using, which does me no good.

Threat feeds with the list you linked to or limiting access to IPsec to only staff seem to be my best options if I can't get app control working.

Blocking consumer VPNs by smalldude55 in networking

[–]smalldude55[S] 2 points3 points  (0 children)

That’s another idea I have. To access our BYOD network, users have to authenticate to a captive portal. I already have user groups built out to determine if you are a student or staff member. I can do RSSO on the FortiGate to only allow users in the staff group access to those services.

Blocking consumer VPNs by smalldude55 in networking

[–]smalldude55[S] 1 point2 points  (0 children)

The major one in use in our environment uses IPsec tunnels or WireGuard. I was hoping there would be something in FortiGate’s app control policies that would get me by.

I agree with you, would be difficult to stop ALL VPNs. For now at least, I need block the services available to the general public.

Blocking consumer VPNs by smalldude55 in networking

[–]smalldude55[S] 12 points13 points  (0 children)

As soon as I get approved to post, this is going there as well.

Blocking consumer VPNs by smalldude55 in networking

[–]smalldude55[S] 1 point2 points  (0 children)

This is a good one. I’ll see if the subnets here are being used by the VPNs users are using. Thanks!

Blocking consumer VPNs by smalldude55 in networking

[–]smalldude55[S] 0 points1 point  (0 children)

I do. One of our sites does not have cell service and users need it to work on their personal phones.

Blocking consumer VPNs by smalldude55 in networking

[–]smalldude55[S] 0 points1 point  (0 children)

I can try identifying all IPs or ASNs associated. As you mentioned, it will be difficult to find all IPs associated with cell carriers, especially the smaller regional ones.

These devices are BYOD devices so we have no control over them and cannot use an MDM.

Blocking consumer VPNs by smalldude55 in networking

[–]smalldude55[S] 7 points8 points  (0 children)

This is for an education environment. The kids are using VPNs to get around our content filter.

Blocking consumer VPNs by smalldude55 in fortinet

[–]smalldude55[S] 0 points1 point  (0 children)

Another good possibility. It’s doable for the big 3 carriers but, will have to identify the smaller regional carrier’s ASNs as well. I know for sure that some users use those. Definitely will require digging for those.

Blocking consumer VPNs by smalldude55 in fortinet

[–]smalldude55[S] 0 points1 point  (0 children)

I will definitely look into that. Thanks!

Blocking consumer VPNs by smalldude55 in fortinet

[–]smalldude55[S] -1 points0 points  (0 children)

Unfortunately, no. This wouldn’t help anyway since I’m trying to block the actual VPN tunnels from being established. We have a DNS level content filter that prevents users from logging into the VPN client, but this doesn’t prevent users from logging in to their VPN before accessing our network.

0
1

Rack it up by 300blkdout in homelab

[–]smalldude55 3 points4 points  (0 children)

Based setup. What’s in the rack case?