Community discussions

MikroTik App
 
mazinsaeed
newbie
Topic Author
Posts: 41
Joined: Wed Oct 16, 2013 4:55 pm

vpn blocking

Tue Aug 05, 2014 8:27 am

Hi , is there anyway to block the vpn program on my server ?
 
User avatar
docmarius
Forum Guru
Forum Guru
Posts: 1224
Joined: Sat Nov 06, 2010 12:04 pm
Location: Timisoara, Romania
Contact:

Re: vpn blocking

Tue Aug 05, 2014 9:22 am

Maybe give us more details: What kind of server? Client or server part of VPN? Or maybe forward of VPN? What OS is running on the server?
This is close to "My car won't start! How do I fix it?"
 
mazinsaeed
newbie
Topic Author
Posts: 41
Joined: Wed Oct 16, 2013 4:55 pm

Re: vpn blocking

Tue Aug 05, 2014 11:37 am

Thanks boss , the story is : I live in Iraq and you know about our situation over her , the coverment block some websites like facebook & youtube because some of the people uploading gruesome videos urges to fight , So they blocked the sites mentioned
Some people useing VPN software like hotspot sheild or siphone or super vpn to convert them IP's to another countries like USA or Japan and these programs as you know could unblocking the websites ...

my ask is there anyway to block these program or forward it to block ?

my server is Mikrotik 1100 AH X2 // mipsbe 6.15
 
User avatar
docmarius
Forum Guru
Forum Guru
Posts: 1224
Joined: Sat Nov 06, 2010 12:04 pm
Location: Timisoara, Romania
Contact:

Re: vpn blocking

Tue Aug 05, 2014 6:12 pm

A simple first step would be to block forwarding any protocol except tcp, udp and icmp. This would kill VPNs like PPtP, L2TP, IPIP.
Then you have the remaining issue of VPNs over TCP and UDP.
Here you have to decide. Allow only tcp/http port 80 traffic: put a transparent webproxy online. This will most likely eliminate some of the TCP tunnels. Https is another issue. I'm not sure how this works with https and if the proxy supports it correctly (port which is also used for SSTP ).
For UDP traffic - I am out of clues except port filtering.