This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall rule does not work as expected

Hello,

I'm really not new to the XG system, but right now I got no clue what's going on.
I defined a firewall rule (Test) in my 'exeptions' group. The rule ID is #2:

The destination is a FQDN-hostgroup "Origin" with several FQDN-hosts associated:

The "IP-collector" for the domain "ea.com" for example, works flawless and it collects all the associated IPs automatically:

But when I now start a origin game like "BFV" the "Test" rule (#2) will not be triggered like expected. Instead of the Test rule, the rule with ID6 is triggered:

As you can see, this is a rule I defined under the "Web-Filter" group. It's my HTTPS-scanning rule.

BTW: I use the DPI engine instead of proxy and already defined exeptions for the domains "ea.com" etc. destinations...

What I am doing wrong? Maybe it's really something simple I don't see right now... Confused

Thank you.



This thread was automatically locked due to age.
Parents
  • Hi,

    have you installed the certificate if you are performing scanning?

    ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Yes. I use two certificates. One for the SSL scanning itself and the "web admin certificate" for the user portal because i use the DPI engine and application control.
    In the past i could reproduce an error during the EAP phase for v18. When the connection got intermitted for scanning, i got an certificate error until i defined a web admin certificate with alternate name and then rolled it out on the client. Since then it works flawless.
    But i guess this a antoher story. Grin

Reply
  • Yes. I use two certificates. One for the SSL scanning itself and the "web admin certificate" for the user portal because i use the DPI engine and application control.
    In the past i could reproduce an error during the EAP phase for v18. When the connection got intermitted for scanning, i got an certificate error until i defined a web admin certificate with alternate name and then rolled it out on the client. Since then it works flawless.
    But i guess this a antoher story. Grin

Children
No Data