- CheckMates
- :
- Products
- :
- General Topics
- :
- Application Control can not catch Opera web browse...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Application Control can not catch Opera web browser VPN
Hello,
I am trying to block Facebook and any other social site from our internal network. Also we blocking all Anonymizer and Tunnels Application group.
But users are using Opera Web Browser's default VPN proxy extension. They surfing over internet.
Application Control has already Opera applications signature. Unfortunately Check Point can't catch the Opera VPN connections.
Rule on Firewall:
On Opera Browser:
Settings > Privacy & Security > Enable VPN
Result:
Next Step:
I did HTTPS Inspection on my PC. Finally Firewall detecting Opera VPN and rule working.
But we don't want to use HTTPS Inspection.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just block these domains and you are fine:
- api.surfeasy.com
- de0.opera-proxy.net
- api.sec-tunnel.com
- sitecheck2.opera.com
- opera-mini.net
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unfortunately, still same
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What is your SmartLog showing for the traffic that is permitted?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No any logs on SmartLog...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Enable logging and also check via fw monitor for related traffic connections.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I used fw monitor on our firewall.
From src=192.168.0.172 to dst=77.111.245.14.
I think it is Proxy server IP. The it sending packet to Facebook.
I blocked 77.111.245.14 IP on rule. But it connecting another IP.
Sorry for my poor English
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Found a solution.
1. Activate “Categorize HTTPS websites” option from Application Control and URL Filter blade advanced settings.
Open Smartconsole > Manage and Settings > Blades > Application Control & URL Filter "Advanced Settings" > Activate “Categorize HTTPS websites”
2. After changes, it isn’t affect immediately and must to wait or clear connection table. But I prefer the reboot
