Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Not working with FortiGuard blocker #104

Open
TheSparrowB opened this issue Jun 10, 2022 · 14 comments
Open

Not working with FortiGuard blocker #104

TheSparrowB opened this issue Jun 10, 2022 · 14 comments

Comments

@TheSparrowB
Copy link

Hi. I ran this software on my workplace PC. I haven't changed any parameters from the plugins.
Then, I configured the proxy (as shown) in the firefox browser.
imagen

But when I try to enter in a blocked page like cuevana, this thing appears.
imagen

Is there a way to make it work to bypass the fortiguard firewall? Am i missing something? Do I need to add an extra plugin?. Please I need help.

@krlvm
Copy link
Owner

krlvm commented Jun 10, 2022

Did FortiGuard install your own certificate for you? Check by opening, for example, GitHub, clicking on the lock icon in the address bar, and viewing certificate details -> issuer.

@TheSparrowB
Copy link
Author

Hi. Thanks for the fast response. This is what it shows.

imagen

@krlvm
Copy link
Owner

krlvm commented Jun 10, 2022

Try to visit the desired site via HTTPS
image

@TheSparrowB
Copy link
Author

Ok. With https the result is the same.

imagen

@krlvm
Copy link
Owner

krlvm commented Jun 10, 2022

You may try to enable SNI Modification, so it will be difficult to detect to which site you are trying to connect.
Use, for example, github.com as fake SNI host.
You will need to import the certificate (powertunnel.pem) to Firefox: instruction

@TheSparrowB
Copy link
Author

Ok. I activated SNI and disabled https chunking.
imagen

Then I added some sites in the blacklist.
imagen

I installed the certificate in the PC with success.
imagen

I imported the .pem file in firefox too. But then when I try to access (i.e. cuevana) then it shows this.
imagen

@krlvm
Copy link
Owner

krlvm commented Jun 10, 2022

Change Spoil SNI to Fake SNI and set github.com as fake SNI host.

@TheSparrowB
Copy link
Author

Ok. I changed it.

imagen

But no changes from previous result.

imagen

@krlvm
Copy link
Owner

krlvm commented Jun 10, 2022

I think the TLS connection is still being interrupted by the firewall.
Something is wrong with the MITM implementation in PowerTunnel >= 2.0, try this version: https://github.com/krlvm/PowerTunnel/releases/tag/v1.14

You will need to install the certificate again

@TheSparrowB
Copy link
Author

Ok. I tried the other version and removed both certificates from broser and local machine. Then installed again. The configuration is like this:
imagen

The blacklist is the same:
imagen

But this time when I activate the proxy on firefox. I don't have access to any webpage. Just localhost.
imagen

This is the error.
imagen

@krlvm
Copy link
Owner

krlvm commented Jun 10, 2022

The blacklist in the old versions that you showed is not needed to unlock something, but on the contrary, to block something.
Shutdown PowerTunnel server, clear the blacklist, uncheck this and try again with cuevana:
image

@TheSparrowB
Copy link
Author

Ok. Cleared the flags.
imagen

Cleared the blacklist.
imagen

Now I have access to other pages but still can't access to cuevana.
imagen

@krlvm
Copy link
Owner

krlvm commented Jun 10, 2022

Apparently they still use SNI filtering, though I can't confirm this as I don't have anywhere to test it.
The last thing worth trying is switching to Erase SNI mode.

@TheSparrowB
Copy link
Author

Ohh well, I tried now with the "erase" mode and still no changes. One thing I noted is that now this error appears in most pages now.

imagen

Well, I think the security is heavy in my workplace so, there's nothing more to do. Thanks for all pal.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants