The TOR client creates its own self-signed SSL certificate using a random common name (domain name) that changes after approximately every 30 minutes. After going around and around with this scenario without success, I decided to try and block access to the TOR exit nodes from our network.

Legitimate Tor users thus have a poor browsing experience given the wide use of CloudFlare's CDN. Tor is a network of distributed nodes that provides greater privacy by encrypting a person's

Best way to block tor on a network? Hello all, I was wondering about the question in the title. I have been googling it and have found many answers that involve deep packet inspection to prevent anyone from using http proxies, ssh tunnels, etc.

The TOR project has an entire FAQ page concerning abuse including a section called "I want to ban the Tor network from my service." where they elaborate on how to identify and block TOR exit nodes and what alternatives there might be to doing so. Also there are currently 400k people using TOR, the USA being #1 with around 14% (60k).