Blocking Ultrasurf
Ultrasurf uses “140300000101″ for SSL ehlo messages. If you can block this signature with the your firewall you can block ultrasurf. To do this follow these steps:
- Create a custom object in Firewall/Application Object section. Lets say the name of the object is “Ultra”
- Application object type must be “Custom object”
- Match Type must be “Exact Match”
- Input Representation must be “Hexadecimal”
- Then add Content “140300000101″
- Policy name: write whatever you want
- Policy type “Custom Policy”
- Adress Source “Any”, Destionation “Any”
- Service Source “Any”, Destionation “Any”
- Exclusion Adrsss “None”
- Application Object “Ultra Object” **Select the object which you write in the first section
- Action “Reset/Drop”
- Users/Group Included “All”, Excluded “None”
- Schedule “Always On”
- Enable loging “Check”
- Redundancy Filters “Use Global settings checked”
- Connection Side “Client Side”
- Direction “Basic” Both
0 comments:
Post a Comment