Wehave submitted to PAN to create an application for this as one does not currently exist, but we need to block this in the mean time. I know we can create a custom application for this, but I am not experienced enough to put in the details for this so it only affects that application.
You're tagging each of these objects with a "vyprvpn" tag for a good reason. The above process will create one address object per server location. You then create an Address Group that includes all of the individual address objects tagged with 'vyprvpn' like this:
EDIT: I assumed that the VyprVPN server was hosted by
goldenfrog.com in my above instructions. You may need to do something similar for VyprVPN through giganews, ie:
us1.vpn.giganews.com, but the concept is the same.
Also, I did a couple of quick tests.. VyprVPN on iOS is detected as "ciscovpn" and "ipsec-esp-udp" from an AppID perspective. Block those Apps to shut this down on that platform. On Windows, the VyprVPN "Chameleon" protocol is detected as "unknown-udp" and can also be blocked. In my lab, blocking unknown-udp prevented VyprVPN from establishing a Chameleon VPN tunnel without worrying about destination IP addresses.
I'm not very familiar with the Arch package managers but it appears that the newly update vyprvpn command line tools PKGBUILD reports it can be updated to 1.7.2. but installs 1.7.1 which is causing a loop of continuous upgrades that never actually happen. I have uninstalled, rebooted and reinstalled to verify. I also replicated the problem on another machine.
The steps to replicate:1. remove the vyprvpn package via 'yaourt -R vyprvpn-linux-cli'2. install the application again 'yaourt vyprvpn-linux-cli'3. running 'yaourt -S vyprvpn-linux-cli' prompts for an upgrade to 1.7.2
@cagprado Thanks for your suggestions! I did find that post while I was looking for solutions previously. They only officially support Ubuntu/Mint so I didn't bother reaching out to them. I was on a three day trial, so when I couldn't figure it out within the three days, I cancelled and said it was because I couldn't get it to work on Arch. They didn't bother reaching out to me, so I guess they don't care too much, LOL.
3a8082e126