> Source: [sk184854](https://support.checkpoint.com/results/sk/sk184854)

# sk184854 - "Block Psiphon" Application Controle rule in SmartConsole does not block traffic from Psiphon application as expected

| Property | Value |
|----------|-------|
| Solution ID | sk184854 |
| Date Created | 2026-03-27 |
| Last Modified | 2026-04-20 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- A Security Gateway does not block traffic for the "Psiphon" application even though there is an explicit Application Control rule to drop Psiphon traffic.

## Cause

In addition to the "Block Psiphon" Application Control rule, HTTPS Inspection and additional Access Control Rules are necessary to block Psiphon.

## Solution

1. In SmartConsole, make sure that HTTPS Inspection is enabled for the relevant traffic. For more information, see the Threat Prevention Administration Guide for your version \> HTTPS Inspection section. For example, see the R82.10 documentation [here](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_ThreatPrevention_AdminGuide/Content/Topics-TPG/Using_Threat_Prevention_with_HTTPS_Traffic.htm?Highlight=https%20inspection).
2. Make sure these Access Control Rules are in the Access Control Policy, in the order shown in this example:  
   * Rule 1: \[Services \& Applications: ssh_version_2\] \[Action: Drop\]
   * Rule 2: \[Services \& Applications: Unknown Traffic\] \[Action: Drop\]
   * Rule 3: \[Service: Quic Protocol\] \[Action: Drop\]
   * Rule 4: Service: \[Psiphon\] \[Action: Drop\]

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1774646544711/Untitled picture202603271638091.png)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
