Skip to main navigation menu Skip to main content Skip to site footer

ANALYTICAL STUDY FOR DETECTING VPN-BASED FIREWALL BYPASS IN ENTERPRISE NETWORKS: A TRAFFIC FLOW INVESTIGATION USING UNIFI UDM PRO

Abstract

A firewall is a device that we use to protect our network and devices from unauthorized access. It controls user access to different platforms (Websites/Applications) by applying security policies. On the other hands VPN (Virtual Private Networks) are commonly used to create secure transmission through encrypted tunnels. However, the use of VPNs introduces significant challenges for network administrators and firewall systems. When a client activates a Public/Third-party VPN connection, network traffic is routed through an encrypted tunnel. And it will limit the visibility of the firewall and bypass the firewall policies. As a result, traditional firewall mechanisms may fail to enforce security policies effectively. This study analyses the limitations of firewall visibility under VPN traffic tunnelling by Third-Party VPNs. A real-world experimental setup is implemented using the Ubiquiti UniFi Dream Machine Pro, where security policies are configured, and system behaviour is observed before and after VPN activation. Based on the findings, we propose a layered base detection approach that identifies firewall blind spots and detects VPN traffic. An allow-list is used to make sure that trusted business VPN traffic is not identified as unauthorized VPN traffic.

Keywords

Firewall, VPN, visibility, Tunnelling, UDM Pro, TLS, Signature matching

PDF