- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
BLOCK PSIPHON VPN
I am trying to block Psiphon VPN on a Check Point firewall, but I am facing an issue.
I first attempted to block Psiphon using Application Control & URL Filtering.
The rule shows Drop logs, however Psiphon VPN continues to work at the user end.
Next, I enabled HTTPS Inspection and applied a block policy.
The logs show traffic as Inspected, but Psiphon VPN is still able to connect successfully.
I think that Psiphon VPN is bypassing the Check Point firewall, even though the logs indicate the traffic is being dropped/inspected.
Could anyone please advise on this,
Is there a recommended or proven method to block Psiphon VPN on Check Point?
Is this a known limitation, and should this be raised with Check Point TAC?
Any inputs or best-practice recommendations would be greatly appreciated.
I assume R81.20, then?
From recent TAC cases, it seems others are experiencing similar issues.
Problems blocking this app have been reported several times over the last few years.
Suggest opening a TAC case so we can investigate further.
We are missing some detail for us to be able to help effectively:
- What additional blades are enabled?
- What does the access policy look like for outbound traffic including things like SSH, QUIC etc?
- What version/JHF is the gateway?
Hi Chris,
1 the enabled blades are firewall,IPSEC VPN,Mobile access,APCL & URLF,Monitoring and we did the https inspection
2 the outbound traffic including things like 80,443,53 and we blocked the QUIC protocol
3 Next we created a HTTPS inspection rule with any services & default services and set the rule to inspect but still its working perfectly.
4 Gateways are installed with JHF T119
I assume R81.20, then?
From recent TAC cases, it seems others are experiencing similar issues.
Problems blocking this app have been reported several times over the last few years.
Suggest opening a TAC case so we can investigate further.
Independent of your special use case, there is an old thread apparently discussing same topic:
Solved: Block Psiphon 2023 - Check Point CheckMates
Solution was an offline package to update the Psiphon signature. Maybe it fits to your case, then contacting TAC would be a good idea.
Is this what you used?
yes this is the application Iam trying to Block
Another thing I would try is also add custom app group and include *psiphon* in it and see if that works by blocking it.
Hi Rock,
I tried with custom application group,URL, categories as well.. but still its same
I cant able to block this Application with the CP firewall
Do you have https inspection enabled? Nm, I see you do...I would open TAC case and see what they say.
yes I have enabled the HTTPS INSPECTION! and the VPN is not blocked by CP firewall.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 64 | |
| 23 | |
| 13 | |
| 12 | |
| 11 | |
| 9 | |
| 8 | |
| 7 | |
| 7 | |
| 7 |
Tue 21 Apr 2026 @ 05:00 PM (IDT)
AI Security Masters E7: How CPR Broke ChatGPT's Isolation and What It Means for YouTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 21 Apr 2026 @ 05:00 PM (IDT)
AI Security Masters E7: How CPR Broke ChatGPT's Isolation and What It Means for YouTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY