How to successfully block Psiphon VPN in the security policy
1263
Created On 05/05/22 23:29 PM - Last Modified 03/11/25 23:22 PM
Objective
To Block Psiphon VPN using firewall Security Policy.
Environment
- Palo Alto Firewalls
- Supported PAN-OS
- Decryption
- SSL Forward Proxy
Procedure
- Configure a Decryption profile for decrypting traffic in the desired zones.
- Name the clone profile as Psiphon-decrypt-profile (or any name you want).
- Under SSL Decryption > SSL Forward Proxy:
- Under Server Certificate Verification:
- Check: Block sessions with expired certificates
- Block sessions with untrusted issuers
- Block sessions with unknown certificate status
- Block sessions on certificate status check timeout
- Under Unsupported Mode Checks
- Check: Block sessions with unsupported versions
- Block sessions with unsupported cipher suites
- Under Server Certificate Verification:
- Commit the changes.