1. Network firewall
– Configure edge firewall or routing to device to only allow the proxy to send traffic to the Internet using the allowed ports (80, 443, 21 and 53).

Implementing the three-step solution discussed above prevented a test workstation from being able to use either Ultrasurf or Freegate to reach Internet content.

I don’t have URL license, I’m using only application filters. So I blocked all proxy and encrypted tunnels applications. and it doesn’t work.

