Community discussions

MikroTik App
 
abuumarselo
newbie
Topic Author
Posts: 34
Joined: Wed Aug 21, 2019 3:11 pm

How I can block VPN progrmas

Wed Sep 04, 2019 11:22 am

hi

I need to block VPN access for all computers in my network and allow only that who need it for work

How I can do that I have rb2011 V6.45.2
 
pe1chl
Forum Guru
Forum Guru
Posts: 10216
Joined: Mon Jun 08, 2015 12:09 pm

Re: How I can block VPN progrmas

Wed Sep 04, 2019 12:04 pm

That really isn't possible...
 
abuumarselo
newbie
Topic Author
Posts: 34
Joined: Wed Aug 21, 2019 3:11 pm

Re: How I can block VPN progrmas

Wed Sep 04, 2019 12:17 pm

please explain why

I saw a video on you tube blocking some ports for vpn access such as pptp but I need to see it again
 
pe1chl
Forum Guru
Forum Guru
Posts: 10216
Joined: Mon Jun 08, 2015 12:09 pm

Re: How I can block VPN progrmas  [SOLVED]

Wed Sep 04, 2019 1:07 pm

There are so many VPN programs and so many that use common ports like 443 that it is impossible to block them.
There are even VPN programs that work via DNS! Those often even work when you have a hotspot and the user has no account/ticket.

Really, when you "need to block" you should not offer internet access at all.
 
abuumarselo
newbie
Topic Author
Posts: 34
Joined: Wed Aug 21, 2019 3:11 pm

Re: How I can block VPN progrmas

Wed Sep 04, 2019 1:30 pm

thank you
 
User avatar
JohnTRIVOLTA
Member
Member
Posts: 345
Joined: Sun Dec 25, 2016 2:05 pm
Location: BG/Sofia

Re: How I can block VPN progrmas

Wed Sep 04, 2019 1:53 pm

The correct method is to allow the necessary services and then block all other traffic on forward chain!
 
pe1chl
Forum Guru
Forum Guru
Posts: 10216
Joined: Mon Jun 08, 2015 12:09 pm

Re: How I can block VPN progrmas

Wed Sep 04, 2019 7:35 pm

The correct method is to allow the necessary services and then block all other traffic on forward chain!
But that is usually not practical either. There is no easy way to allow a service like a generic website, and even allowing
generic services like a DNS resolver which recurses to internet DNS (rather than serving only static names) will open up your
router for determined people wanting to setup a VPN.

Who is online

Users browsing this forum: No registered users and 32 guests