How to Block I2P traffic using App Control Advanced
03/26/2020
7 People found this article helpful
194,945 Views
Description
The Invisible Internet Project (I2P) is an anonymous network, exposing a simple layer that applications can use to anonymously and securely send messages to each other. This KB articles describes how to block I2P traffic.
These are the signatures to be enabled for effectively blocking I2P traffic:
- PROXY-ACCESS | I2P signatures - These signatures identify legitimate (and illegitimate) I2P Proxy Access requests, e.g. GET http://www.domain.com/resource.i2p/abc. This signature does not identify or block encrypted I2P tunnels
- PROXY-ACCESS | Encrypted Key Exchange -- UDP Random Encryption - SID 7 blocks UDP tunnel traffic. Enabling this signature will not only block encrypted I2P traffic over UDB but also block other encrypted UDP traffic like IPSec VPN traffic passing through the SonicWall. Before enabling this signature, exclude the outside or inside IP addresses of legitimiate IPSec traffic.
- PROXY-ACCESS | Encrypted Key Exchange -- TCP Random Encryption - SID 5 blocks TCP tunnel traffic. Enabling this signature will not only block encrypted I2P traffic over TCP but also block other encrypted TCP traffic passing through the SonicWall. Before enabling this signature, exclude the outside or inside IP addresses of such legitimiate traffic.
Resolution
- Login to the SonicWall Management GUI.
- Navigate to the Firewall | App Control Advanced page. In Gen5 TZ devices this page is under Security Services | App Control
- Check the box under Enable App Control and click on the Accept button at the top to enable App Control.
- Under App Control Advanced | View Style select PROXY-ACCESS under Category;
- From the drop-down under Application, select I2P.
- Click on Configure
- In the new window, select Enable under the Block and Log fields.
- Click on OK to save
- In the Lookup Signature ID field, enter 5
- Click on the search icon
- In the new window, select Enable under the Block and Log fields.
- Click on OK to save

- In the Lookup Signature ID field, enter 7
- Click on the search icon
- In the new window, select Enable under the Block and Log fields.
- Click on OK to save
Enabling Application Control Service on zones
- Navigate to Network | Zones
- Click on the configure button under the zone where you want to enable App Control.
- Check Enable App Control Service.
- Click on OK to save.

Related Articles
Categories
Was This Article Helpful?
YES
NO