- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
BLOCK PSIPHON VPN
I am trying to block Psiphon VPN on a Check Point firewall, but I am facing an issue.
I first attempted to block Psiphon using Application Control & URL Filtering.
The rule shows Drop logs, however Psiphon VPN continues to work at the user end.
Next, I enabled HTTPS Inspection and applied a block policy.
The logs show traffic as Inspected, but Psiphon VPN is still able to connect successfully.
I think that Psiphon VPN is bypassing the Check Point firewall, even though the logs indicate the traffic is being dropped/inspected.
Could anyone please advise on this,
Is there a recommended or proven method to block Psiphon VPN on Check Point?
Is this a known limitation, and should this be raised with Check Point TAC?
Any inputs or best-practice recommendations would be greatly appreciated.
I assume R81.20, then?
From recent TAC cases, it seems others are experiencing similar issues.
Problems blocking this app have been reported several times over the last few years.
Suggest opening a TAC case so we can investigate further.
We are missing some detail for us to be able to help effectively:
- What additional blades are enabled?
- What does the access policy look like for outbound traffic including things like SSH, QUIC etc?
- What version/JHF is the gateway?
Hi Chris,
1 the enabled blades are firewall,IPSEC VPN,Mobile access,APCL & URLF,Monitoring and we did the https inspection
2 the outbound traffic including things like 80,443,53 and we blocked the QUIC protocol
3 Next we created a HTTPS inspection rule with any services & default services and set the rule to inspect but still its working perfectly.
4 Gateways are installed with JHF T119
I assume R81.20, then?
From recent TAC cases, it seems others are experiencing similar issues.
Problems blocking this app have been reported several times over the last few years.
Suggest opening a TAC case so we can investigate further.
Independent of your special use case, there is an old thread apparently discussing same topic:
Solved: Block Psiphon 2023 - Check Point CheckMates
Solution was an offline package to update the Psiphon signature. Maybe it fits to your case, then contacting TAC would be a good idea.
Is this what you used?
yes this is the application Iam trying to Block
Another thing I would try is also add custom app group and include *psiphon* in it and see if that works by blocking it.
Hi Rock,
I tried with custom application group,URL, categories as well.. but still its same
I cant able to block this Application with the CP firewall
Do you have https inspection enabled? Nm, I see you do...I would open TAC case and see what they say.
yes I have enabled the HTTPS INSPECTION! and the VPN is not blocked by CP firewall.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 14 | |
| 10 | |
| 10 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 |
Tue 19 May 2026 @ 06:00 PM (IDT)
AI Security Masters E8 - Claude Mythos: New Era in Cyber SecurityWed 20 May 2026 @ 11:00 AM (CEST)
The New DDoS Reality: Autonomy, Scale, and the Future of DefenceTue 19 May 2026 @ 06:00 PM (IDT)
AI Security Masters E8 - Claude Mythos: New Era in Cyber SecurityWed 20 May 2026 @ 11:00 AM (CEST)
The New DDoS Reality: Autonomy, Scale, and the Future of DefenceFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY