<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Block Tor traffic completely on R80.40 gateways in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122014#M17439</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;does oneone have a solution for blocking tor traffic completely on R80.40 gateways?&lt;/P&gt;&lt;P&gt;I have followed the steps decribed in sk103154 "How to block traffic coming from known malicious IP addresses" but I am still able to connect to the TOR network by using the "Tor is censored in my country - select a built in bridge: meek-azure (works in China)" feature of the TOR browser.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;</description>
    <pubDate>Thu, 24 Jun 2021 10:49:57 GMT</pubDate>
    <dc:creator>Stefan_Schmidt</dc:creator>
    <dc:date>2021-06-24T10:49:57Z</dc:date>
    <item>
      <title>Block Tor traffic completely on R80.40 gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122014#M17439</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;does oneone have a solution for blocking tor traffic completely on R80.40 gateways?&lt;/P&gt;&lt;P&gt;I have followed the steps decribed in sk103154 "How to block traffic coming from known malicious IP addresses" but I am still able to connect to the TOR network by using the "Tor is censored in my country - select a built in bridge: meek-azure (works in China)" feature of the TOR browser.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 10:49:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122014#M17439</guid>
      <dc:creator>Stefan_Schmidt</dc:creator>
      <dc:date>2021-06-24T10:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: Block Tor traffic completely on R80.40 gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122068#M17456</link>
      <description>&lt;P&gt;I recommend engaging with the TAC on this.&lt;BR /&gt;That said, it's possible this mechanism might also block legitimate uses of Azure, which is possibly why this is still allowed.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 15:33:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122068#M17456</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-24T15:33:00Z</dc:date>
    </item>
    <item>
      <title>Re: Block Tor traffic completely on R80.40 gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122079#M17459</link>
      <description>&lt;P&gt;You need HTTPS Inspection to fully block TOR&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 16:05:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122079#M17459</guid>
      <dc:creator>Benedikt_Weissl</dc:creator>
      <dc:date>2021-06-24T16:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: Block Tor traffic completely on R80.40 gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122149#M17475</link>
      <description>&lt;P&gt;what should the HTTPS inspection rule look like that you have in mind? Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 06:26:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122149#M17475</guid>
      <dc:creator>Stefan_Schmidt</dc:creator>
      <dc:date>2021-06-25T06:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: Block Tor traffic completely on R80.40 gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122152#M17476</link>
      <description>&lt;P&gt;It was matched by the catch-all rule, the rulebase in my lab (and also productive enviroment) is structered so that bypass rules come first, the rest is matched by a catch-all rule.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 06:55:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122152#M17476</guid>
      <dc:creator>Benedikt_Weissl</dc:creator>
      <dc:date>2021-06-25T06:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: Block Tor traffic completely on R80.40 gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122182#M17483</link>
      <description>&lt;P&gt;The directions in that article describe how to block traffic coming from people who use TOR&amp;nbsp;&lt;EM&gt;into&lt;/EM&gt; your environment. It wouldn't have any effect at all on traffic from your users out.&lt;/P&gt;
&lt;P&gt;To block traffic&amp;nbsp;&lt;EM&gt;from&lt;/EM&gt; your environment out to TOR, you will need HTTPS inspection and a rule blocking or rejecting the "Tor" (and probably "&lt;SPAN&gt;Invisible Browsing", "Tails", and "Tor2Web"&lt;/SPAN&gt;) application/site object.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 14:23:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122182#M17483</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-06-25T14:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: Block Tor traffic completely on R80.40 gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122218#M17484</link>
      <description>&lt;P&gt;Im not positive thats actually true...why would you need https inspection to block tor traffic?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 18:34:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122218#M17484</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-06-25T18:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: Block Tor traffic completely on R80.40 gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122222#M17485</link>
      <description>&lt;P&gt;Not sure if this makes sense, but if you have app control enabled, can you try add that application to be blocked?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 19:19:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122222#M17485</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-06-25T19:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: Block Tor traffic completely on R80.40 gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122710#M17558</link>
      <description>&lt;P&gt;Hello Bob,&lt;/P&gt;&lt;P&gt;I did all that now but I am still able to connect to the TOR network by using the "Tor is censored in my country - select a built in bridge: meek-azure (works in China)" feature of the TOR browser.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 11:43:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122710#M17558</guid>
      <dc:creator>Stefan_Schmidt</dc:creator>
      <dc:date>2021-07-01T11:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: Block Tor traffic completely on R80.40 gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122729#M17559</link>
      <description>&lt;P&gt;Since the traffic is encrypted and the AppControl pattern doesn't match if I choose the "Tor is censored in my country - select a built in bridge: meek-azure (works in China)"-option. At least in my lab enviroment, R81 gw and sms. &lt;BR /&gt;&lt;BR /&gt;If i activate https inspection the tor browser won't connect anymore and a bypass is impossible.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 14:42:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122729#M17559</guid>
      <dc:creator>Benedikt_Weissl</dc:creator>
      <dc:date>2021-07-01T14:42:51Z</dc:date>
    </item>
    <item>
      <title>Re: Block Tor traffic completely on R80.40 gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122777#M17569</link>
      <description>&lt;P&gt;And that traffic may not look like Tor traffic.&lt;BR /&gt;Recommend a TAC case here.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 22:28:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Tor-traffic-completely-on-R80-40-gateways/m-p/122777#M17569</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-01T22:28:38Z</dc:date>
    </item>
  </channel>
</rss>

