This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Deleted firewall rule works even after reboot - XG106

Hello community,

we have a strange issue with our XG106 hardware appliance (SFOS 18.0.3 MR-3):

After deleting a firewall rule (HTTPS) the service is still accessible - even after a reboot. Only after disabling the NAT rule, the service is inaccessible, but this should not be the normale behaviour.

The rule doesn't exist anymore in the XML export file.

Maybe someone can help, thanks in advance

Aiko



This thread was automatically locked due to age.
Parents
  • Hi,

    when you filter on 443 in logviewer which rule do see being used?
    ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Hi, thanks for your reply.

    Unfortunately I can't see any entries for HTTPS. If I create the HTTPS rule again and activate logging, this rule is in use.

  • Hi,

    so what that implies is the sessions were not ended or that you have another rule eg SSL/TLS inspection active. I find there is something odd with the sessions remaining after a reboot and the firewall rule deleted.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • For testing purpose I have created a drop rule for HTTPS and put it at the first position.

    The page still opens and the firewall logs "Allowed" for rule ID 8.

    The rules are okay, we have another appliance with identical rules:
    Disabling HTTPS: site unreachable
    Rule condition drop: site unreachable

    I think this is a bug. Maybe because we have restored this appliance from a backup?



    table header
    [edited by: Stadt Leer at 11:28 AM (GMT -7) on 15 Oct 2020]
  • Hi,

    that rule is fr incoming traffic, not outgoing traffic which is what I assumed your issue is?

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

Reply Children