This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

UDP DNAT Rule works, but FW do not "see" packets?

Hello,

 

i'm trying to understand following behavior:

DNAT rule created for port 12345 UDP. Automatic Firewall rule is on. Log checked.

I'm able to see initial packet log and also other packets:

18:50:49     NAT rule #1     UDP            80.187.105.131:15746     →      80.147.xxx.xxx:12345            len=42     ttl=50     tos=0x00

18:54:54     Auto-generated rule #4     UDP            80.187.105.131:15746     →      10.17.42.17:12345            len=109     ttl=49     tos=0x00     srcmac=00:1a:8c:f0:a8:c4

Nice, after this i disable autmatic FW rule, so it disappear. And create the same rule manual on the top, with DROP and log checked.

Traffic pass trough, and leave no logs.

Any suggestions WHY?

 

Regards



This thread was automatically locked due to age.
  • Tried all to block DNATted traffic, no luck so far:

  • Rule #6 has no effect.  Rule #5 is pre-empted by your DNAT, so it also has no effect.  See #2 in Rulz.

    How long after you made rule #4 did you wait before testing?  WebAdmin is a GUI that manipulates databases of objects and settings.  A single change there can cause the Configuration Daemon to rewrite hundreds of lines of the code used to run the UTM.

    I'm assuming that "DMZ-RC1" does not violate #3 in Rulz - is that correct?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA