This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG135w connection breaking up

Hello,

I'm experiencing sudden break ups witht he connection with my XG135w.

The configuration is as follows: ISP model with optical connection - unmanaged switch (with nothing else connected except ISP modem and XG) - XG - couple of switches with PoE and two Ubiquiti AP.

It all started on friday last week when I wanted to configure my two Ubiquiti APs with additional Guest WiFi network (with our existing one). After that the Ubiquiti APs started breaking up, so I deleted the newly created Guest WiFi, but after this I realised that our XG is always breaking up the connection to the internet. COuple of times it was WAN interface down, then it was okay but the connection was just broken for couple of seconds (without messaging that the WAN is down), then it went up for another couple of minutes, than breaks and so on (often with the message DNS_PROBE_FINISHED_NXDOMAIN after trying to refresh a site or to open a new one).

We have a ESXi on the network that has a AD virtual machine. The XG has a static DNS IP address set.

I'm not sure where to look at. It was all running smoothly before this Ubiquiti thing. Tried one more time to play with MTU (it was 1500) or to add a second rule to the WAN link manager for going down, but without help.

Any suggestions?

Thank you!



This thread was automatically locked due to age.
Parents Reply Children
  • We had the issues also i n the last couple of hours

  • Couple or exactly 2 hours, cause the reports is show for last 2 hours, I would suggest generate it for last 24 hours !! 

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Technical Account Manager 3 | Cyber Security Evolved


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Hello Vivek,

    here is for the last 48 hours:

  • Memory/CPU looks fine, but the WAN data transfer seems to be on a peak when the issue occurs !! 
    What type of authentication is being used  for the users to access internet ?
    Under the FW rule , do you use web/app/IPS or scanning ? 

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Technical Account Manager 3 | Cyber Security Evolved


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • There is no real authentification, as son as you connect to any of the outlets in the office or via WiFi, you have the ability to access internet.

    Regarding FW rule, I need to check this one and give an edit.

  • Please check and perform a packet capture from the diagnostics to see if it is not causing any violation !!

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Technical Account Manager 3 | Cyber Security Evolved


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Just checked the web/app/IPS, everything okay, like it was before when it worked (for two years), no changes.

    I've started packet capture, going to check, when the first break apperas, what is says.

    Could it be with dynamic DNS? We had some problems with it a while ago (two months), it would break the connections, but that it worked for some time.

  • May be may be not, let's perform a packet capture during the break from the diagnostics.
    From the CLI, check for the drop-packet-capture: https://support.sophos.com/support/s/article/KB-000036858?language=en_US
    And also conntrack: https://community.sophos.com/sophos-xg-firewall/f/recommended-reads/117389/sophos-xg-cli-troubleshooting-tools

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Technical Account Manager 3 | Cyber Security Evolved


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Since it's complicated to that exactly the moment when the drop happends (today it lasts for only 3-4 seconds according to my colleagues), I took some that I think were part of the drop.

    Here are some of CLI outputs for your suggested commands.

    Conntrack:

    proto=tcp      proto-no=6 timeout=10799 state=ESTABLISHED orig-src=10.27.27.106 
    orig-dst=20.82.247.128 orig-sport=63599 orig-dport=443 packets=2464 bytes=174110
     reply-src=20.82.247.128 reply-dst=192.168.1.2 reply-sport=443 reply-dport=63599
     packets=11353 bytes=16037318 [ASSURED] mark=0x8001 use=1 id=1481722368 masterid
    =0 devin=Port1 devout=Port2 nseid=0 ips=0 sslvpnid=0 webfltid=0 appfltid=0 icapi
    d=0 policytype=1 fwid=5 natid=1 fw_action=1 bwid=0 appid=100 appcatid=5 hbappid=
    0 hbappcatid=0 dpioffload=0x3f sigoffload=0 inzone=1 outzone=2 devinindex=5 devo
    utindex=6 hb_src=0 hb_dst=0 flags0=0x800a080020000a flags1=0x52002a00018 flagval
    ues=1,3,21,35,41,43,55,67,68,85,87,89,101,104,106 catid=0 user=0 luserid=0 userg
    p=0 hotspotuserid=0 hotspotid=0 dst_mac=7c:5a:1c:7d:5f:ad src_mac=00:50:b6:9b:55
    :c7 startstamp=1659340513 microflowid[0]=503 microflowrev[0]=11 microflowid[1]=1
    587 microflowrev[1]=5 hostrev[0]=31 hostrev[1]=31 ipspid=0 diffserv=0 loindex=6 
    tlsruleid=0 ips_nfqueue=3 sess_verdict=2 gwoff=0 cluster_node=0 current_state[0]
    =18 current_state[1]=18 vlan_id=0 inmark=0x0 brinindex=25 sessionid=29 sessionid
    rev=28236 session_update_rev=6 dnat_done=0 upclass=0:0 dnclass=0:0 pbrid_dir0=0 
    pbrid_dir1=0 nhop_id[0]=39 nhop_id[1]=65535 nhop_rev[0]=0 nhop_rev[1]=0 conn_fp_
    id=NOT_OFFLOADED                                                                
    proto=tcp      proto-no=6 timeout=56 state=LAST_ACK orig-src=192.168.1.2 orig-ds
    t=195.29.179.143 orig-sport=47698 orig-dport=80 packets=11 bytes=1456 reply-src=
    195.29.179.143 reply-dst=192.168.1.2 reply-sport=80 reply-dport=47698 packets=10
     bytes=7716 [ASSURED] mark=0x8001 use=1 id=1454865920 masterid=560186624 devin= 
    devout=Port2 nseid=0 ips=0 sslvpnid=0 webfltid=0 appfltid=0 icapid=0 policytype=
    1 fwid=5 natid=1 fw_action=0 bwid=0 appid=2174 appcatid=5 hbappid=0 hbappcatid=0
     dpioffload=0x3f sigoffload=0 inzone=1 outzone=0 devinindex=0 devoutindex=6 hb_s
    rc=0 hb_dst=0 flags0=0x80020000280809 flags1=0x10002800000 flagvalues=0,3,11,19,
    21,41,55,87,89,104 catid=29 user=0 luserid=0 usergp=0 hotspotuserid=0 hotspotid=
    0 dst_mac=7c:5a:1c:7d:5f:ad src_mac=00:50:56:bc:ea:84 startstamp=1659341371 micr
    oflow[0]=INVALID microflow[1]=INVALID hostrev[0]=0 hostrev[1]=0 ipspid=0 diffser
    v=0 loindex=0 tlsruleid=0 ips_nfqueue=1 sess_verdict=2 gwoff=0 cluster_node=0 cu
    rrent_state[0]=18 current_state[1]=18 vlan_id=0 inmark=0x0 brinindex=0 sessionid
    =3075 sessionidrev=55011 session_update_rev=5 dnat_done=0 upclass=0:0 dnclass=0:
    0 pbrid_dir0=0 pbrid_dir1=0 conn_fp_id=NOT_OFFLOADED                            
    proto=tcp      proto-no=6 timeout=9 state=TIME_WAIT orig-src=10.27.27.106 orig-d
    st=10.27.27.2 orig-sport=50569 orig-dport=4444 packets=6 bytes=776 reply-src=10.
    27.27.2 reply-dst=10.27.27.106 reply-sport=65003 reply-dport=50569 packets=4 byt
    es=309 [ASSURED] mark=0x0 use=1 id=2548414080 masterid=0 devin=Port1 devout= nse
    id=0 ips=0 sslvpnid=0 webfltid=0 appfltid=0 icapid=0 policytype=0 fwid=0 natid=0
     fw_action=0 bwid=0 appid=0 appcatid=0 hbappid=0 hbappcatid=0 dpioffload=0 sigof
    fload=0 inzone=1 outzone=4 devinindex=5 devoutindex=0 hb_src=0 hb_dst=0 flags0=0
    x800208000 flags1=0x40400000000 flagvalues=15,21,35,98,106 catid=0 user=0 luseri
    d=0 usergp=0 hotspotuserid=0 hotspotid=0 dst_mac=7c:5a:1c:7d:5f:ad src_mac=00:50
    :b6:9b:55:c7 startstamp=1659341444 microflow[0]=INVALID microflow[1]=INVALID hos
    trev[0]=0 hostrev[1]=0 ipspid=0 diffserv=0 loindex=25 tlsruleid=0 ips_nfqueue=0 
    sess_verdict=0 gwoff=0 cluster_node=0 current_state[0]=0 current_state[1]=18 vla
    n_id=0 inmark=0x0 brinindex=25 sessionid=92 sessionidrev=51664 session_update_re
    v=0 dnat_done=0 upclass=0:0 dnclass=0:0 pbrid_dir0=0 pbrid_dir1=0 conn_fp_id=NOT
    _OFFLOADED                                                                      
    proto=tcp      proto-no=6 timeout=10797 state=ESTABLISHED orig-src=10.27.27.127 
    orig-dst=8.8.8.8 orig-sport=58680 orig-dport=853 packets=11 bytes=1201 reply-src
    =8.8.8.8 reply-dst=192.168.1.2 reply-sport=853 reply-dport=58680 packets=11 byte
    s=6388 [ASSURED] mark=0x8001 use=1 id=3640590336 masterid=0 devin=Port1 devout=P
    ort2 nseid=0 ips=0 sslvpnid=0 webfltid=0 appfltid=0 icapid=0 policytype=1 fwid=5
     natid=1 fw_action=1 bwid=0 appid=2974 appcatid=5 hbappid=0 hbappcatid=0 dpioffl
    oad=0x3b sigoffload=0 inzone=1 outzone=2 devinindex=5 devoutindex=6 hb_src=0 hb_
    dst=0 flags0=0x800a080020000a flags1=0x52000a00018 flagvalues=1,3,21,35,41,43,55
    ,67,68,85,87,101,104,106 catid=0 user=0 luserid=0 usergp=0 hotspotuserid=0 hotsp
    otid=0 dst_mac=7c:5a:1c:7d:5f:ad src_mac=98:0d:51:68:f3:71 startstamp=1659341427
     microflowid[0]=129 microflowrev[0]=6 microflowid[1]=1733 microflowrev[1]=42 hos
    trev[0]=2 hostrev[1]=2 ipspid=0 diffserv=0 loindex=6 tlsruleid=0 ips_nfqueue=2 s
    ess_verdict=0 gwoff=0 cluster_node=0 current_state[0]=18 current_state[1]=18 vla
    n_id=0 inmark=0x0 brinindex=25 sessionid=3981 sessionidrev=10590 session_update_
    rev=5 dnat_done=0 upclass=0:0 dnclass=0:0 pbrid_dir0=0 pbrid_dir1=0 nhop_id[0]=3
    9 nhop_id[1]=65535 nhop_rev[0]=0 nhop_rev[1]=0 conn_fp_id=NOT_OFFLOADED         
    proto=tcp      proto-no=6 timeout=1 state=TIME_WAIT orig-src=10.27.27.106 orig-d
    st=10.27.27.2 orig-sport=50501 orig-dport=4444 packets=8 bytes=1923 reply-src=10
    .27.27.2 reply-dst=10.27.27.106 reply-sport=65003 reply-dport=50501 packets=7 by
    tes=789 [ASSURED] mark=0x0 use=1 id=1409504256 masterid=0 devin=Port1 devout= ns
    eid=0 ips=0 sslvpnid=0 webfltid=0 appfltid=0 icapid=0 policytype=0 fwid=0 natid=
    0 fw_action=0 bwid=0 appid=0 appcatid=0 hbappid=0 hbappcatid=0 dpioffload=0 sigo
    ffload=0 inzone=1 outzone=4 devinindex=5 devoutindex=0 hb_src=0 hb_dst=0 flags0=
    0x800208000 flags1=0x40400000000 flagvalues=15,21,35,98,106 catid=0 user=0 luser
    id=0 usergp=0 hotspotuserid=0 hotspotid=0 dst_mac=7c:5a:1c:7d:5f:ad src_mac=00:5
    0:b6:9b:55:c7 startstamp=1659341436 microflow[0]=INVALID microflow[1]=INVALID ho
    strev[0]=0 hostrev[1]=0 ipspid=0 diffserv=0 loindex=25 tlsruleid=0 ips_nfqueue=0
     sess_verdict=0 gwoff=0 cluster_node=0 current_state[0]=0 current_state[1]=18 vl
    an_id=0 inmark=0x0 brinindex=25 sessionid=3554 sessionidrev=53462 session_update
    _rev=0 dnat_done=0 upclass=0:0 dnclass=0:0 pbrid_dir0=0 pbrid_dir1=0 conn_fp_id=
    NOT_OFFLOADED                                                                   
    proto=udp      proto-no=17 timeout=23 orig-src=192.168.1.2 orig-dst=8.8.8.8 orig
    -sport=24654 orig-dport=53 packets=1 bytes=110 reply-src=8.8.8.8 reply-dst=192.1
    68.1.2 reply-sport=53 reply-dport=24654 packets=1 bytes=192 mark=0x8001 helper=d
    ns use=1 id=1454652928 masterid=0 devin= devout=Port2 nseid=0 ips=0 sslvpnid=0 w
    ebfltid=0 appfltid=0 icapid=0 policytype=0 fwid=0 natid=0 fw_action=0 bwid=0 app
    id=0 appcatid=0 hbappid=0 hbappcatid=0 dpioffload=0 sigoffload=0 inzone=0 outzon
    e=0 devinindex=0 devoutindex=6 hb_src=0 hb_dst=0 flags0=0x200000 flags1=0x0 flag
    values=21 catid=0 user=0 luserid=0 usergp=0 hotspotuserid=0 hotspotid=0 dst_mac=
    7c:5a:1c:7d:5f:ae src_mac=44:22:7c:ab:c6:38 startstamp=1659341438 microflow[0]=I
    NVALID microflow[1]=INVALID hostrev[0]=0 hostrev[1]=0 ipspid=0 diffserv=0 loinde
    x=0 tlsruleid=0 ips_nfqueue=0 sess_verdict=0 gwoff=0 cluster_node=0 current_stat
    e[0]=18 current_state[1]=18 vlan_id=0 inmark=0x0 brinindex=0 sessionid=1604 sess
    ionidrev=53323 session_update_rev=0 dnat_done=0 upclass=0:0 dnclass=0:0 pbrid_di
    r0=0 pbrid_dir1=0 conn_fp_id=NOT_OFFLOADED                                      
    proto=tcp      proto-no=6 timeout=10756 state=ESTABLISHED orig-src=10.27.27.122 
    orig-dst=8.8.4.4 orig-sport=51198 orig-dport=443 packets=26 bytes=2708 reply-src
    =8.8.4.4 reply-dst=192.168.1.2 reply-sport=443 reply-dport=51198 packets=34 byte
    s=4680 [ASSURED] mark=0x8001 use=1 id=567736896 masterid=0 devin=Port1 devout=Po
    rt2 nseid=0 ips=0 sslvpnid=0 webfltid=0 appfltid=0 icapid=0 policytype=1 fwid=5 
    natid=1 fw_action=1 bwid=0 appid=100 appcatid=5 hbappid=0 hbappcatid=0 dpioffloa
    d=0x3f sigoffload=0 inzone=1 outzone=2 devinindex=5 devoutindex=6 hb_src=0 hb_ds
    t=0 flags0=0x800a080020000a flags1=0x52002a00018 flagvalues=1,3,21,35,41,43,55,6
    7,68,85,87,89,101,104,106 catid=0 user=0 luserid=0 usergp=0 hotspotuserid=0 hots
    potid=0 dst_mac=7c:5a:1c:7d:5f:ad src_mac=e8:6a:64:f5:cb:78 startstamp=165934109
    0 microflowid[0]=568 microflowrev[0]=51 microflowid[1]=1473 microflowrev[1]=17 h
    ostrev[0]=8 hostrev[1]=8 ipspid=0 diffserv=0 loindex=6 tlsruleid=0 ips_nfqueue=3
     sess_verdict=2 gwoff=0 cluster_node=0 current_state[0]=18 current_state[1]=18 v
    lan_id=0 inmark=0x0 brinindex=25 sessionid=4099 sessionidrev=28422 session_updat
    e_rev=6 dnat_done=0 upclass=0:0 dnclass=0:0 pbrid_dir0=0 pbrid_dir1=0 nhop_id[0]
    =39 nhop_id[1]=65535 nhop_rev[0]=0 nhop_rev[1]=0 conn_fp_id=NOT_OFFLOADED       
    proto=tcp      proto-no=6 timeout=10783 state=ESTABLISHED orig-src=192.168.1.2 o
    rig-dst=34.104.35.123 orig-sport=56678 orig-dport=80 packets=4 bytes=542 reply-s
    rc=34.104.35.123 reply-dst=192.168.1.2 reply-sport=80 reply-dport=56678 packets=
    3 bytes=683 [ASSURED] mark=0x8001 use=1 id=3640597056 masterid=1060553984 devin=
     devout=Port2 nseid=0 ips=0 sslvpnid=0 webfltid=0 appfltid=0 icapid=0 policytype
    =1 fwid=5 natid=1 fw_action=0 bwid=0 appid=2174 appcatid=5 hbappid=0 hbappcatid=
    0 dpioffload=0xd sigoffload=0 inzone=1 outzone=0 devinindex=0 devoutindex=6 hb_s
    rc=0 hb_dst=0 flags0=0x80020000280809 flags1=0x10000800000 flagvalues=0,3,11,19,
    21,41,55,87,104 catid=29 user=0 luserid=0 usergp=0 hotspotuserid=0 hotspotid=0 d
    st_mac=7c:5a:1c:7d:5f:ad src_mac=18:1d:ea:fe:1f:aa startstamp=1659341428 microfl
    ow[0]=INVALID microflow[1]=INVALID hostrev[0]=0 hostrev[1]=0 ipspid=0 diffserv=0
     loindex=0 tlsruleid=0 ips_nfqueue=1 sess_verdict=0 gwoff=0 cluster_node=0 curre
    nt_state[0]=18 current_state[1]=18 vlan_id=0 inmark=0x0 brinindex=0 sessionid=39
    84 sessionidrev=10602 session_update_rev=3 dnat_done=0 upclass=0:0 dnclass=0:0 p
    brid_dir0=0 pbrid_dir1=0 conn_fp_id=NOT_OFFLOADED                               
    proto=tcp      proto-no=6 timeout=10698 state=ESTABLISHED orig-src=10.27.27.101 
    orig-dst=34.149.211.227 orig-sport=59257 orig-dport=443 packets=41 bytes=17821 r
    eply-src=34.149.211.227 reply-dst=192.168.1.2 reply-sport=443 reply-dport=59257 
    packets=37 bytes=9463 [ASSURED] mark=0x8001 use=1 id=1454858880 masterid=0 devin
    =Port1 devout=Port2 nseid=0 ips=0 sslvpnid=0 webfltid=0 appfltid=0 icapid=0 poli
    cytype=1 fwid=5 natid=1 fw_action=1 bwid=0 appid=2731 appcatid=13 hbappid=0 hbap
    pcatid=0 dpioffload=0xf sigoffload=0x5 inzone=1 outzone=2 devinindex=5 devoutind
    ex=6 hb_src=0 hb_dst=0 flags0=0x800a080020000a flags1=0x52002a00018 flagvalues=1
    ,3,21,35,41,43,55,67,68,85,87,89,101,104,106 catid=0 user=0 luserid=0 usergp=0 h
    otspotuserid=0 hotspotid=0 dst_mac=7c:5a:1c:7d:5f:ad src_mac=3c:a9:f4:86:41:c0 s
    tartstamp=1659340561 microflowid[0]=1456 microflowrev[0]=9 microflowid[1]=1574 m
    icroflowrev[1]=52 hostrev[0]=8 hostrev[1]=8 ipspid=0 diffserv=0 loindex=6 tlsrul
    eid=0 ips_nfqueue=0 sess_verdict=2 gwoff=0 cluster_node=0 current_state[0]=18 cu
    rrent_state[1]=18 vlan_id=0 inmark=0x0 brinindex=25 sessionid=3722 sessionidrev=
    58039 session_update_rev=6 dnat_done=0 upclass=0:0 dnclass=0:0 pbrid_dir0=0 pbri
    d_dir1=0 nhop_id[0]=39 nhop_id[1]=65535 nhop_rev[0]=0 nhop_rev[1]=0 conn_fp_id=N
    OT_OFFLOADED                                                                    
    proto=tcp      proto-no=6 timeout=10789 state=ESTABLISHED orig-src=10.27.27.107 
    orig-dst=31.13.84.8 orig-sport=58215 orig-dport=443 packets=133 bytes=11754 repl
    y-src=31.13.84.8 reply-dst=192.168.1.2 reply-sport=443 reply-dport=58215 packets
    =165 bytes=105123 [ASSURED] mark=0x8001 use=2 id=1060559424 masterid=0 devin=Por
    t1 devout=Port2 nseid=0 ips=0 sslvpnid=0 webfltid=0 appfltid=0 icapid=0 policyty
    pe=1 fwid=5 natid=1 fw_action=1 bwid=0 appid=220 appcatid=19 hbappid=0 hbappcati
    d=0 dpioffload=0x3f sigoffload=0 inzone=1 outzone=2 devinindex=5 devoutindex=6 h
    b_src=0 hb_dst=0 flags0=0x800a080020000a flags1=0x52002a00018 flagvalues=1,3,21,
    35,41,43,55,67,68,85,87,89,101,104,106 catid=0 user=0 luserid=0 usergp=0 hotspot
    userid=0 hotspotid=0 dst_mac=7c:5a:1c:7d:5f:ad src_mac=18:1d:ea:fe:1f:aa startst
    amp=1659341163 microflowid[0]=1260 microflowrev[0]=13 microflowid[1]=1722 microf
    lowrev[1]=15 hostrev[0]=8 hostrev[1]=9 ipspid=0 diffserv=0 loindex=6 tlsruleid=0
     ips_nfqueue=0 sess_verdict=2 gwoff=0 cluster_node=0 current_state[0]=18 current
    _state[1]=18 vlan_id=0 inmark=0x0 brinindex=25 sessionid=3727 sessionidrev=58011
     session_update_rev=6 dnat_done=0 upclass=0:0 dnclass=0:0 pbrid_dir0=0 pbrid_dir
    1=0 nhop_id[0]=39 nhop_id[1]=65535 nhop_rev[0]=0 nhop_rev[1]=0 conn_fp_id=NOT_OF
    FLOADED                                                                         
    proto=tcp      proto-no=6 timeout=7555 state=ESTABLISHED orig-src=10.27.27.144 o
    rig-dst=20.199.120.151 orig-sport=49676 orig-dport=443 packets=12 bytes=2756 rep
    ly-src=20.199.120.151 reply-dst=192.168.1.2 reply-sport=443 reply-dport=49676 pa
    ckets=14 bytes=5609 [ASSURED] mark=0x8001 use=1 id=1454542592 masterid=0 devin=P
    ort1 devout=Port2 nseid=0 ips=0 sslvpnid=0 webfltid=0 appfltid=0 icapid=0 policy
    type=1 fwid=5 natid=1 fw_action=1 bwid=0 appid=2730 appcatid=3 hbappid=0 hbappca
    tid=0 dpioffload=0xf sigoffload=0x5 inzone=1 outzone=2 devinindex=5 devoutindex=
    6 hb_src=0 hb_dst=0 flags0=0x800a080020000a flags1=0x52002a00018 flagvalues=1,3,
    21,35,41,43,55,67,68,85,87,89,101,104,106 catid=0 user=0 luserid=0 usergp=0 hots
    potuserid=0 hotspotid=0 dst_mac=7c:5a:1c:7d:5f:ad src_mac=00:50:56:bc:ea:84 star
    tstamp=1659338199 microflowid[0]=1689 microflowrev[0]=8 microflowid[1]=1590 micr
    oflowrev[1]=16 hostrev[0]=1 hostrev[1]=1 ipspid=0 diffserv=0 loindex=6 tlsruleid
    =0 ips_nfqueue=1 sess_verdict=2 gwoff=0 cluster_node=0 current_state[0]=14 curre
    nt_state[1]=14 vlan_id=0 inmark=0x0 brinindex=25 sessionid=3266 sessionidrev=161
    57 session_update_rev=6 dnat_done=0 upclass=0:0 dnclass=0:0 pbrid_dir0=0 pbrid_d
    ir1=0 nhop_id[0]=39 nhop_id[1]=65535 nhop_rev[0]=0 nhop_rev[1]=0 conn_fp_id=NOT_
    OFFLOADED                                                                       
    proto=udp      proto-no=17 timeout=12 orig-src=192.168.1.2 orig-dst=8.8.8.8 orig
    -sport=30238 orig-dport=53 packets=1 bytes=84 reply-src=8.8.8.8 reply-dst=192.16
    8.1.2 reply-sport=53 reply-dport=30238 packets=1 bytes=148 mark=0x8001 helper=dn
    s use=1 id=1454650688 masterid=0 devin= devout=Port2 nseid=0 ips=0 sslvpnid=0 we
    bfltid=0 appfltid=0 icapid=0 policytype=0 fwid=0 natid=0 fw_action=0 bwid=0 appi
    d=0 appcatid=0 hbappid=0 hbappcatid=0 dpioffload=0 sigoffload=0 inzone=0 outzone
    =0 devinindex=0 devoutindex=6 hb_src=0 hb_dst=0 flags0=0x200000 flags1=0x0 flagv
    alues=21 catid=0 user=0 luserid=0 usergp=0 hotspotuserid=0 hotspotid=0 dst_mac=7
    c:5a:1c:7d:5f:ae src_mac=44:22:7c:ab:c6:38 startstamp=1659341427 microflow[0]=IN
    VALID microflow[1]=INVALID hostrev[0]=0 hostrev[1]=0 ipspid=0 diffserv=0 loindex
    =0 tlsruleid=0 ips_nfqueue=0 sess_verdict=0 gwoff=0 cluster_node=0 current_state
    [0]=18 current_state[1]=18 vlan_id=0 inmark=0x0 brinindex=0 sessionid=571 sessio
    nidrev=58232 session_update_rev=0 dnat_done=0 upclass=0:0 dnclass=0:0 pbrid_dir0
    =0 pbrid_dir1=0 conn_fp_id=NOT_OFFLOADED                                        
    proto=tcp      proto-no=6 timeout=3 state=CLOSE orig-src=10.27.27.2 orig-dst=10.
    27.27.6 orig-sport=37912 orig-dport=389 packets=8 bytes=457 reply-src=10.27.27.6
     reply-dst=10.27.27.2 reply-sport=389 reply-dport=37912 packets=6 bytes=452 [ASS
    URED] mark=0x0 use=1 id=2548408320 masterid=0 devin= devout=br0 nseid=0 ips=0 ss
    lvpnid=0 webfltid=0 appfltid=0 icapid=0 policytype=0 fwid=0 natid=0 fw_action=0 
    bwid=0 appid=0 appcatid=0 hbappid=0 hbappcatid=0 dpioffload=0 sigoffload=0 inzon
    e=0 outzone=0 devinindex=0 devoutindex=25 hb_src=0 hb_dst=0 flags0=0x200000 flag
    s1=0x0 flagvalues=21 catid=0 user=0 luserid=0 usergp=0 hotspotuserid=0 hotspotid
    =0 dst_mac=7c:5a:1c:7d:5f:ad src_mac=00:0c:29:a3:96:91 startstamp=1659341438 mic
    roflow[0]=INVALID microflow[1]=INVALID hostrev[0]=0 hostrev[1]=0 ipspid=0 diffse
    rv=0 loindex=0 tlsruleid=0 ips_nfqueue=0 sess_verdict=0 gwoff=0 cluster_node=0 c
    urrent_state[0]=18 current_state[1]=18 vlan_id=0 inmark=0x0 brinindex=0 sessioni
    d=3126 sessionidrev=13526 session_update_rev=0 dnat_done=0 upclass=0:0 dnclass=0
    :0 pbrid_dir0=0 pbrid_dir1=0 conn_fp_id=NOT_OFFLOADED                           
    proto=tcp      proto-no=6 timeout=3 state=TIME_WAIT orig-src=10.27.27.106 orig-d
    st=10.27.27.2 orig-sport=50510 orig-dport=4444 packets=8 bytes=1923 reply-src=10
    .27.27.2 reply-dst=10.27.27.106 reply-sport=65003 reply-dport=50510 packets=7 by
    tes=789 [ASSURED] mark=0x0 use=1 id=1060555264 masterid=0 devin=Port1 devout= ns
    eid=0 ips=0 sslvpnid=0 webfltid=0 appfltid=0 icapid=0 policytype=0 fwid=0 natid=
    0 fw_action=0 bwid=0 appid=0 appcatid=0 hbappid=0 hbappcatid=0 dpioffload=0 sigo
    ffload=0 inzone=1 outzone=4 devinindex=5 devoutindex=0 hb_src=0 hb_dst=0 flags0=
    0x800208000 flags1=0x40400000000 flagvalues=15,21,35,98,106 catid=0 user=0 luser
    id=0 usergp=0 hotspotuserid=0 hotspotid=0 dst_mac=7c:5a:1c:7d:5f:ad src_mac=00:5
    0:b6:9b:55:c7 startstamp=1659341438 microflow[0]=INVALID microflow[1]=INVALID ho
    strev[0]=0 hostrev[1]=0 ipspid=0 diffserv=0 loindex=25 tlsruleid=0 ips_nfqueue=0
     sess_verdict=0 gwoff=0 cluster_node=0 current_state[0]=0 current_state[1]=18 vl
    an_id=0 inmark=0x0 brinindex=25 sessionid=3132 sessionidrev=13996 session_update
    _rev=0 dnat_done=0 upclass=0:0 dnclass=0:0 pbrid_dir0=0 pbrid_dir1=0 conn_fp_id=
    NOT_OFFLOADED                                                                   
    proto=tcp      proto-no=6 timeout=10789 state=ESTABLISHED orig-src=10.27.27.106 
    orig-dst=142.250.180.194 orig-sport=50321 orig-dport=443 packets=6 bytes=922 rep
    ly-src=142.250.180.194 reply-dst=192.168.1.2 reply-sport=443 reply-dport=50321 p
    ackets=5 bytes=1050 [ASSURED] mark=0x8001 use=1 id=4026984640 masterid=0 devin=P
    ort1 devout=Port2 nseid=0 ips=0 sslvpnid=0 webfltid=0 appfltid=0 icapid=0 policy
    type=1 fwid=5 natid=1 fw_action=1 bwid=0 appid=100 appcatid=5 hbappid=0 hbappcat
    id=0 dpioffload=0xd sigoffload=0 inzone=1 outzone=2 devinindex=5 devoutindex=6 h
    b_src=0 hb_dst=0 flags0=0x800a080020000a flags1=0x52000a00018 flagvalues=1,3,21,
    35,41,43,55,67,68,85,87,101,104,106 catid=0 user=0 luserid=0 usergp=0 hotspotuse
    rid=0 hotspotid=0 dst_mac=7c:5a:1c:7d:5f:ad src_mac=00:50:b6:9b:55:c7 startstamp
    =1659341389 microflowid[0]=458 microflowrev[0]=39 microflowid[1]=1377 microflowr
    ev[1]=13 hostrev[0]=2 hostrev[1]=2 ipspid=0 diffserv=0 loindex=6 tlsruleid=0 ips
    _nfqueue=0 sess_verdict=0 gwoff=0 cluster_node=0 current_state[0]=18 current_sta
    te[1]=18 vlan_id=0 inmark=0x0 brinindex=25 sessionid=878 sessionidrev=33899 sess
    ion_update_rev=3 dnat_done=0 upclass=0:0 dnclass=0:0 pbrid_dir0=0 pbrid_dir1=0 n
    hop_id[0]=39 nhop_id[1]=65535 nhop_rev[0]=0 nhop_rev[1]=0 conn_fp_id=NOT_OFFLOAD
    ED                                                                              
    proto=tcp      proto-no=6 timeout=10797 state=ESTABLISHED orig-src=10.27.27.107 
    orig-dst=31.13.84.23 orig-sport=58214 orig-dport=443 packets=1455 bytes=309765 r
    eply-src=31.13.84.23 reply-dst=192.168.1.2 reply-sport=443 reply-dport=58214 pac
    kets=1668 bytes=115248 [ASSURED] mark=0x8001 use=1 id=1412506240 masterid=0 devi
    n=Port1 devout=Port2 nseid=0 ips=0 sslvpnid=0 webfltid=0 appfltid=0 icapid=0 pol
    icytype=1 fwid=5 natid=1 fw_action=1 bwid=0 appid=220 appcatid=19 hbappid=0 hbap
    pcatid=0 dpioffload=0x3f sigoffload=0 inzone=1 outzone=2 devinindex=5 devoutinde
    x=6 hb_src=0 hb_dst=0 flags0=0x800a080020000a flags1=0x52002a00018 flagvalues=1,
    3,21,35,41,43,55,67,68,85,87,89,101,104,106 catid=0 user=0 luserid=0 usergp=0 ho
    tspotuserid=0 hotspotid=0 dst_mac=7c:5a:1c:7d:5f:ad src_mac=18:1d:ea:fe:1f:aa st
    artstamp=1659341163 microflowid[0]=1515 microflowrev[0]=21 microflowid[1]=1615 m
    icroflowrev[1]=33 hostrev[0]=7 hostrev[1]=7 ipspid=0 diffserv=0 loindex=6 tlsrul
    eid=0 ips_nfqueue=3 sess_verdict=2 gwoff=0 cluster_node=0 current_state[0]=18 cu
    rrent_state[1]=18 vlan_id=0 inmark=0x0 brinindex=25 sessionid=3530 sessionidrev=
    31817 session_update_rev=6 dnat_done=0 upclass=0:0 dnclass=0:0 pbrid_dir0=0 pbri
    d_dir1=0 nhop_id[0]=39 nhop_id[1]=65535 nhop_rev[0]=0 nhop_rev[1]=0 conn_fp_id=N
    OT_OFFLOADED                                                                    
    proto=tcp      proto-no=6 timeout=10288 state=ESTABLISHED orig-src=10.27.27.107 
    orig-dst=20.199.120.182 orig-sport=56209 orig-dport=443 packets=18 bytes=3516 re
    ply-src=20.199.120.182 reply-dst=192.168.1.2 reply-sport=443 reply-dport=56209 p
    ackets=15 bytes=5750 [ASSURED] mark=0x8001 use=1 id=1987231232 masterid=0 devin=
    Port1 devout=Port2 nseid=0 ips=0 sslvpnid=0 webfltid=0 appfltid=0 icapid=0 polic
    ytype=1 fwid=5 natid=1 fw_action=1 bwid=0 appid=2730 appcatid=3 hbappid=0 hbappc
    atid=0 dpioffload=0xf sigoffload=0x5 inzone=1 outzone=2 devinindex=5 devoutindex
    =6 hb_src=0 hb_dst=0 flags0=0x800a080020000a flags1=0x52002a00018 flagvalues=1,3
    ,21,35,41,43,55,67,68,85,87,89,101,104,106 catid=0 user=0 luserid=0 usergp=0 hot
    spotuserid=0 hotspotid=0 dst_mac=7c:5a:1c:7d:5f:ad src_mac=18:1d:ea:fe:1f:aa sta
    rtstamp=1659338040 microflowid[0]=1391 microflowrev[0]=50 microflowid[1]=698 mic
    roflowrev[1]=45 hostrev[0]=3 hostrev[1]=3 ipspid=0 diffserv=0 loindex=6 tlsrulei
    d=0 ips_nfqueue=2 sess_verdict=2 gwoff=0 cluster_node=0 current_state[0]=18 curr
    ent_state[1]=18 vlan_id=0 inmark=0x0 brinindex=25 sessionid=2605 sessionidrev=28
    195 session_update_rev=6 dnat_done=0 upclass=0:0 dnclass=0:0 pbrid_dir0=0 pbrid_
    dir1=0 nhop_id[0]=39 nhop_id[1]=65535 nhop_rev[0]=0 nhop_rev[1]=0 conn_fp_id=NOT
    _OFFLOADED                                                                      
    proto=tcp      proto-no=6 timeout=10765 state=ESTABLISHED orig-src=10.27.27.101 
    orig-dst=8.8.8.8 orig-sport=59319 orig-dport=443 packets=14 bytes=1621 reply-src
    =8.8.8.8 reply-dst=192.168.1.2 reply-sport=443 reply-dport=59319 packets=16 byte
    s=2507 [ASSURED] mark=0x8001 use=1 id=975251968 masterid=0 devin=Port1 devout=Po
    rt2 nseid=0 ips=0 sslvpnid=0 webfltid=0 appfltid=0 icapid=0 policytype=1 fwid=5 
    natid=1 fw_action=1 bwid=0 appid=100 appcatid=5 hbappid=0 hbappcatid=0 dpioffloa
    d=0x3f sigoffload=0 inzone=1 outzone=2 devinindex=5 devoutindex=6 hb_src=0 hb_ds
    t=0 flags0=0x800a080020000a flags1=0x52002a00018 flagvalues=1,3,21,35,41,43,55,6
    7,68,85,87,89,101,104,106 catid=0 user=0 luserid=0 usergp=0 hotspotuserid=0 hots
    potid=0 dst_mac=7c:5a:1c:7d:5f:ad src_mac=3c:a9:f4:86:41:c0 startstamp=165934123
    0 microflowid[0]=416 microflowrev[0]=23 microflowid[1]=1779 microflowrev[1]=46 h
    ostrev[0]=5 hostrev[1]=5 ipspid=0 diffserv=0 loindex=6 tlsruleid=0 ips_nfqueue=2
     sess_verdict=2 gwoff=0 cluster_node=0 current_state[0]=18 current_state[1]=18 v
    lan_id=0 inmark=0x0 brinindex=25 sessionid=856 sessionidrev=24285 session_update
    _rev=6 dnat_done=0 upclass=0:0 dnclass=0:0 pbrid_dir0=0 pbrid_dir1=0 nhop_id[0]=
    39 nhop_id[1]=65535 nhop_rev[0]=0 nhop_rev[1]=0 conn_fp_id=NOT_OFFLOADED        
    proto=tcp      proto-no=6 timeout=10766 state=ESTABLISHED orig-src=10.27.27.106 
    orig-dst=91.211.75.130 orig-sport=61975 orig-dport=443 packets=434 bytes=27947 r
    eply-src=91.211.75.130 reply-dst=192.168.1.2 reply-sport=443 reply-dport=61975 p
    ackets=2277 bytes=2771138 [ASSURED] mark=0x8001 use=1 id=1971575360 masterid=0 d
    evin=Port1 devout=Port2 nseid=0 ips=0 sslvpnid=0 webfltid=0 appfltid=0 icapid=0 
    policytype=1 fwid=5 natid=1 fw_action=1 bwid=0 appid=100 appcatid=5 hbappid=0 hb
    appcatid=0 dpioffload=0x3f sigoffload=0 inzone=1 outzone=2 devinindex=5 devoutin
    dex=6 hb_src=0 hb_dst=0 flags0=0x800a080020000a flags1=0x52002a00018 flagvalues=
    1,3,21,35,41,43,55,67,68,85,87,89,101,104,106 catid=0 user=0 luserid=0 usergp=0 
    hotspotuserid=0 hotspotid=0 dst_mac=7c:5a:1c:7d:5f:ad src_mac=00:50:b6:9b:55:c7 
    startstamp=1659339755 microflowid[0]=656 microflowrev[0]=46 microflowid[1]=837 m
    icroflowrev[1]=25 hostrev[0]=42 hostrev[1]=41 ipspid=0 diffserv=0 loindex=6 tlsr
    uleid=0 ips_nfqueue=0 sess_verdict=2 gwoff=0 cluster_node=0 current_state[0]=18 
    current_state[1]=18 vlan_id=0 inmark=0x0 brinindex=25 sessionid=1543 sessionidre
    v=55086 session_update_rev=6 dnat_done=0 upclass=0:0 dnclass=0:0 pbrid_dir0=0 pb
    rid_dir1=0 nhop_id[0]=39 nhop_id[1]=65535 nhop_rev[0]=0 nhop_rev[1]=0 conn_fp_id
    =NOT_OFFLOADE

    Drop-packet-capture interface Port2 (this is WAN)

    2022-08-01 10:29:25 0103021 IP 192.168.1.112.40968 > 255.255.255.255.10001 : pro
    to UDP: packet len: 188 checksum : 36450                                        
    0x0000:  4500 00d0 8e62 4000 4011 e9a2 c0a8 0170  E....b@.@......p              
    0x0010:  ffff ffff a008 2711 00bc 8e62 0206 00b0  ......'....b....              
    0x0020:  0200 0ad0 21f9 b1e5 1cc0 a801 7001 0006  ....!.......p...              
    0x0030:  d021 f9b1 e51c 0a00 0400 0d0b 370b 0007  .!..........7...              
    0x0040:  5536 2d4c 6974 650c 0004 5541 4c36 0300  U6-Lite...UAL6..              
    0x0050:  2242 5a2e 6d74 3736 3231 5f36 2e30 2e32  "BZ.mt7621_6.0.2              
    0x0060:  312b 3133 3637 332e 3232 3036 3037 2e32  1+13673.220607.2              
    0x0070:  3030 3416 000c 362e 302e 3231 2e31 3336  004...6.0.21.136              
    0x0080:  3733 1500 0455 414c 3617 0001 0018 0001  73...UAL6.......              
    0x0090:  0019 0001 011a 0001 0113 0006 d021 f9b1  .............!..              
    0x00a0:  e51c 1200 0400 029a b51b 0006 352e 3239  ............5.29              
    0x00b0:  2e30 2700 08e4 b012 b246 5b07 e92a 0010  .0'......F[..*..              
    0x00c0:  467d a608 13f2 452e 84b0 12b2 465b 07e9  F}....E.....F[..              
    Date=2022-08-01 Time=10:29:25 log_id=0103021 log_type=Firewall log_component=Loc
    al_ACLs log_subtype=Denied log_status=N/A log_priority=Alert duration=N/A in_dev
    =Port2 out_dev= inzone_id=2 outzone_id=4 source_mac=d0:21:f9:b1:e5:1c dest_mac=f
    f:ff:ff:ff:ff:ff bridge_name= l3_protocol=IPv4 source_ip=192.168.1.112 dest_ip=2
    55.255.255.255 l4_protocol=UDP source_port=40968 dest_port=10001 fw_rule_id=N/A 
    policytype=0 live_userid=0 userid=0 user_gp=0 ips_id=0 sslvpn_id=0 web_filter_id
    =0 hotspot_id=0 hotspotuser_id=0 hb_src=0 hb_dst=0 dnat_done=0 icap_id=0 app_fil
    ter_id=0 app_category_id=0 app_id=0 category_id=0 bandwidth_id=0 up_classid=0 dn
    _classid=0 nat_id=0 cluster_node=0 inmark=0x8001 nfqueue=0 gateway_offset=0 conn
    id=1058902400 masterid=0 status=256 state=0, flag0=549757911040 flags1=0 pbdid_d
    ir0=0 pbrid_dir1=0                                                              
                                                                                    
    2022-08-01 10:29:26 0103021 IP 184.105.247.199.43981 > 192.168.1.2.5001 : proto 
    TCP: S 2972623788:2972623788(0) win 65535 checksum : 10709                      
    0x0000:  4500 0028 d431 0000 f306 81c2 b869 f7c7  E..(.1.......i..              
    0x0010:  c0a8 0102 abcd 1389 b12e a3ac 0000 0000  ................              
    0x0020:  5002 ffff 29d5 0000                      P...)...                      
    Date=2022-08-01 Time=10:29:26 log_id=0103021 log_type=Firewall log_component=Loc
    al_ACLs log_subtype=Denied log_status=N/A log_priority=Alert duration=N/A in_dev
    =Port2 out_dev= inzone_id=2 outzone_id=4 source_mac=44:22:7c:ab:c6:38 dest_mac=7
    c:5a:1c:7d:5f:ae bridge_name= l3_protocol=IPv4 source_ip=184.105.247.199 dest_ip
    =192.168.1.2 l4_protocol=TCP source_port=43981 dest_port=5001 fw_rule_id=N/A pol
    icytype=0 live_userid=0 userid=0 user_gp=0 ips_id=0 sslvpn_id=0 web_filter_id=0 
    hotspot_id=0 hotspotuser_id=0 hb_src=0 hb_dst=0 dnat_done=0 icap_id=0 app_filter
    _id=0 app_category_id=0 app_id=0 category_id=0 bandwidth_id=0 up_classid=0 dn_cl
    assid=0 nat_id=0 cluster_node=0 inmark=0x8001 nfqueue=0 gateway_offset=0 connid=
    1454647168 masterid=0 status=256 state=1, flag0=549757911040 flags1=17179869184 
    pbdid_dir0=0 pbrid_dir1=0                                                       
                                                                                    
    2022-08-01 10:29:28 0103021 IP 192.168.1.108.55769 > 255.255.255.255.10001 : pro
    to UDP: packet len: 193 checksum : 45973                                        
    0x0000:  4500 00d5 2bc4 4000 4011 4c40 c0a8 016c  E...+.@.@.L@...l              
    0x0010:  ffff ffff d9d9 2711 00c1 b395 0206 00b5  ......'.........              
    0x0020:  0200 0ad0 21f9 5cfe 67c0 a801 6c01 0006  ....!.\.g...l...              
    0x0030:  d021 f95c fe67 0a00 0400 0d0a 270b 0005  .!.\.g......'...              
    0x0040:  5536 2d4c 520c 0007 5541 4c52 3676 3203  U6-LR...UALR6v2.              
    0x0050:  0022 425a 2e4d 5437 3632 325f 362e 302e  ."BZ.MT7622_6.0.              
    0x0060:  3231 2b31 3336 3733 2e32 3230 3630 372e  21+13673.220607.              
    0x0070:  3230 3034 1600 0c36 2e30 2e32 312e 3133  2004...6.0.21.13              
    0x0080:  3637 3315 0007 5541 4c52 3676 3217 0001  673...UALR6v2...              
    0x0090:  0018 0001 0019 0001 011a 0001 0113 0006  ................              
    0x00a0:  d021 f95c fe67 1200 0400 029b 4f1b 0007  .!.\.g......O...              
    0x00b0:  352e 3433 2e33 3727 0008 1e4d e602 d8c7  5.43.37'...M....              
    0x00c0:  e465 2a00 1065 1358 cd13 2849 318e 4de6  .e*..e.X..(I1.M.              
    0x00d0:  02d8 c7e4 65                             ....e                         
    Date=2022-08-01 Time=10:29:28 log_id=0103021 log_type=Firewall log_component=Loc
    al_ACLs log_subtype=Denied log_status=N/A log_priority=Alert duration=N/A in_dev
    =Port2 out_dev= inzone_id=2 outzone_id=4 source_mac=d0:21:f9:5c:fe:67 dest_mac=f
    f:ff:ff:ff:ff:ff bridge_name= l3_protocol=IPv4 source_ip=192.168.1.108 dest_ip=2
    55.255.255.255 l4_protocol=UDP source_port=55769 dest_port=10001 fw_rule_id=N/A 
    policytype=0 live_userid=0 userid=0 user_gp=0 ips_id=0 sslvpn_id=0 web_filter_id
    =0 hotspot_id=0 hotspotuser_id=0 hb_src=0 hb_dst=0 dnat_done=0 icap_id=0 app_fil
    ter_id=0 app_category_id=0 app_id=0 category_id=0 bandwidth_id=0 up_classid=0 dn
    _classid=0 nat_id=0 cluster_node=0 inmark=0x8001 nfqueue=0 gateway_offset=0 conn
    id=1454648128 masterid=0 status=256 state=0, flag0=549757911040 flags1=0 pbdid_d
    ir0=0 pbrid_dir1=0                                                              
                                                                                    
    2022-08-01 10:29:28 0103021 IP 162.142.125.248.8861 > 192.168.1.2.42306 : proto 
    TCP: S 2431145224:2431145224(0) win 1024 checksum : 1109                        
    0x0000:  4500 002c c409 0000 2806 ec91 a28e 7df8  E..,....(.....}.              
    0x0010:  c0a8 0102 229d a542 90e8 5508 0000 0000  ...."..B..U.....              
    0x0020:  6002 0400 0455 0000 0204 0584            `....U......                  
    Date=2022-08-01 Time=10:29:28 log_id=0103021 log_type=Firewall log_component=Loc
    al_ACLs log_subtype=Denied log_status=N/A log_priority=Alert duration=N/A in_dev
    =Port2 out_dev= inzone_id=2 outzone_id=4 source_mac=44:22:7c:ab:c6:38 dest_mac=7
    c:5a:1c:7d:5f:ae bridge_name= l3_protocol=IPv4 source_ip=162.142.125.248 dest_ip
    =192.168.1.2 l4_protocol=TCP source_port=8861 dest_port=42306 fw_rule_id=N/A pol
    icytype=0 live_userid=0 userid=0 user_gp=0 ips_id=0 sslvpn_id=0 web_filter_id=0 
    hotspot_id=0 hotspotuser_id=0 hb_src=0 hb_dst=0 dnat_done=0 icap_id=0 app_filter
    _id=0 app_category_id=0 app_id=0 category_id=0 bandwidth_id=0 up_classid=0 dn_cl
    assid=0 nat_id=0 cluster_node=0 inmark=0x8001 nfqueue=0 gateway_offset=0 connid=
    1616816640 masterid=0 status=256 state=1, flag0=549757911040 flags1=17179869184 
    pbdid_dir0=0 pbrid_dir1=0                                                       
                                                                                    
    2022-08-01 10:29:29 0103021 IP 89.248.165.204.55880 > 192.168.1.2.10436 : proto 
    TCP: S 3720676461:3720676461(0) win 1024 checksum : 1332                        
    0x0000:  4500 0028 9f97 0000 f606 63c9 59f8 a5cc  E..(......c.Y...              
    0x0010:  c0a8 0102 da48 28c4 ddc5 046d 0000 0000  .....H(....m....              
    0x0020:  5002 0400 0534 0000                      P....4..                      
    Date=2022-08-01 Time=10:29:29 log_id=0103021 log_type=Firewall log_component=Loc
    al_ACLs log_subtype=Denied log_status=N/A log_priority=Alert duration=N/A in_dev
    =Port2 out_dev= inzone_id=2 outzone_id=4 source_mac=44:22:7c:ab:c6:38 dest_mac=7
    c:5a:1c:7d:5f:ae bridge_name= l3_protocol=IPv4 source_ip=89.248.165.204 dest_ip=
    192.168.1.2 l4_protocol=TCP source_port=55880 dest_port=10436 fw_rule_id=N/A pol
    icytype=0 live_userid=0 userid=0 user_gp=0 ips_id=0 sslvpn_id=0 web_filter_id=0 
    hotspot_id=0 hotspotuser_id=0 hb_src=0 hb_dst=0 dnat_done=0 icap_id=0 app_filter
    _id=0 app_category_id=0 app_id=0 category_id=0 bandwidth_id=0 up_classid=0 dn_cl
    assid=0 nat_id=0 cluster_node=0 inmark=0x8001 nfqueue=0 gateway_offset=0 connid=
    1454861120 masterid=0 status=256 state=1, flag0=549757911040 flags1=17179869184 
    pbdid_dir0=0 pbrid_dir1=0                                                       
                                                                                    
    2022-08-01 10:29:33 0103021 IP 194.26.29.86.56063 > 192.168.1.2.31101 : proto TC
    P: S 4053988008:4053988008(0) win 1024 checksum : 53758                         
    0x0000:  4500 0028 38eb 0000 ef06 f1c9 c21a 1d56  E..(8..........V              
    0x0010:  c0a8 0102 daff 797d f1a2 f2a8 0000 0000  ......y}........              
    0x0020:  5002 0400 d1fe 0000                      P.......                      
    Date=2022-08-01 Time=10:29:33 log_id=0103021 log_type=Firewall log_component=Loc
    al_ACLs log_subtype=Denied log_status=N/A log_priority=Alert duration=N/A in_dev
    =Port2 out_dev= inzone_id=2 outzone_id=4 source_mac=44:22:7c:ab:c6:38 dest_mac=7
    c:5a:1c:7d:5f:ae bridge_name= l3_protocol=IPv4 source_ip=194.26.29.86 dest_ip=19
    2.168.1.2 l4_protocol=TCP source_port=56063 dest_port=31101 fw_rule_id=N/A polic
    ytype=0 live_userid=0 userid=0 user_gp=0 ips_id=0 sslvpn_id=0 web_filter_id=0 ho
    tspot_id=0 hotspotuser_id=0 hb_src=0 hb_dst=0 dnat_done=0 icap_id=0 app_filter_i
    d=0 app_category_id=0 app_id=0 category_id=0 bandwidth_id=0 up_classid=0 dn_clas
    sid=0 nat_id=0 cluster_node=0 inmark=0x8001 nfqueue=0 gateway_offset=0 connid=16
    16817280 masterid=0 status=256 state=1, flag0=549757911040 flags1=17179869184 pb
    did_dir0=0 pbrid_dir1=0                                                         
                                                                                    
    2022-08-01 10:29:35 0103021 IP 192.168.1.112.43286 > 255.255.255.255.10001 : pro
    to UDP: packet len: 188 checksum : 31060                                        
    0x0000:  4500 00d0 8f5e 4000 4011 e8a6 c0a8 0170  E....^@.@......p              
    0x0010:  ffff ffff a916 2711 00bc 7954 0206 00b0  ......'...yT....              
    0x0020:  0200 0ad0 21f9 b1e5 1cc0 a801 7001 0006  ....!.......p...              
    0x0030:  d021 f9b1 e51c 0a00 0400 0d0b 410b 0007  .!..........A...              
    0x0040:  5536 2d4c 6974 650c 0004 5541 4c36 0300  U6-Lite...UAL6..              
    0x0050:  2242 5a2e 6d74 3736 3231 5f36 2e30 2e32  "BZ.mt7621_6.0.2              
    0x0060:  312b 3133 3637 332e 3232 3036 3037 2e32  1+13673.220607.2              
    0x0070:  3030 3416 000c 362e 302e 3231 2e31 3336  004...6.0.21.136              
    0x0080:  3733 1500 0455 414c 3617 0001 0018 0001  73...UAL6.......              
    0x0090:  0019 0001 011a 0001 0113 0006 d021 f9b1  .............!..              
    0x00a0:  e51c 1200 0400 029a b71b 0006 352e 3239  ............5.29              
    0x00b0:  2e30 2700 08e4 b012 b246 5b07 e92a 0010  .0'......F[..*..              
    0x00c0:  467d a608 13f2 452e 84b0 12b2 465b 07e9  F}....E.....F[..              
    Date=2022-08-01 Time=10:29:35 log_id=0103021 log_type=Firewall log_component=Loc
    al_ACLs log_subtype=Denied log_status=N/A log_priority=Alert duration=N/A in_dev
    =Port2 out_dev= inzone_id=2 outzone_id=4 source_mac=d0:21:f9:b1:e5:1c dest_mac=f
    f:ff:ff:ff:ff:ff bridge_name= l3_protocol=IPv4 source_ip=192.168.1.112 dest_ip=2
    55.255.255.255 l4_protocol=UDP source_port=43286 dest_port=10001 fw_rule_id=N/A 
    policytype=0 live_userid=0 userid=0 user_gp=0 ips_id=0 sslvpn_id=0 web_filter_id
    =0 hotspot_id=0 hotspotuser_id=0 hb_src=0 hb_dst=0 dnat_done=0 icap_id=0 app_fil
    ter_id=0 app_category_id=0 app_id=0 category_id=0 bandwidth_id=0 up_classid=0 dn
    _classid=0 nat_id=0 cluster_node=0 inmark=0x8001 nfqueue=0 gateway_offset=0 conn
    id=1058903680 masterid=0 status=256 state=0, flag0=549757911040 flags1=0 pbdid_d
    ir0=0 pbrid_dir1=0                                                              
                                                                                    
    2022-08-01 10:29:36 0103021 IP 89.248.165.169.53508 > 192.168.1.2.3661 : proto T
    CP: S 2444277217:2444277217(0) win 1024 checksum : 50098                        
    0x0000:  4500 0028 0892 0000 f606 faf1 59f8 a5a9  E..(........Y...              
    0x0010:  c0a8 0102 d104 0e4d 91b0 b5e1 0000 0000  .......M........              
    0x0020:  5002 0400 c3b2 0000                      P.......                      
    Date=2022-08-01 Time=10:29:36 log_id=0103021 log_type=Firewall log_component=Loc
    al_ACLs log_subtype=Denied log_status=N/A log_priority=Alert duration=N/A in_dev
    =Port2 out_dev= inzone_id=2 outzone_id=4 source_mac=44:22:7c:ab:c6:38 dest_mac=7
    c:5a:1c:7d:5f:ae bridge_name= l3_protocol=IPv4 source_ip=89.248.165.169 dest_ip=
    192.168.1.2 l4_protocol=TCP source_port=53508 dest_port=3661 fw_rule_id=N/A poli
    cytype=0 live_userid=0 userid=0 user_gp=0 ips_id=0 sslvpn_id=0 web_filter_id=0 h
    otspot_id=0 hotspotuser_id=0 hb_src=0 hb_dst=0 dnat_done=0 icap_id=0 app_filter_
    id=0 app_category_id=0 app_id=0 category_id=0 bandwidth_id=0 up_classid=0 dn_cla
    ssid=0 nat_id=0 cluster_node=0 inmark=0x8001 nfqueue=0 gateway_offset=0 connid=1
    454646208 masterid=0 status=256 state=1, flag0=549757911040 flags1=17179869184 p
    bdid_dir0=0 pbrid_dir1=0                                                        
                                                                                    
    2022-08-01 10:29:38 0103021 IP 192.168.1.108.57997 > 255.255.255.255.10001 : pro
    to UDP: packet len: 193 checksum : 40673                                        
    0x0000:  4500 00d5 341e 4000 4011 43e6 c0a8 016c  E...4.@.@.C....l              
    0x0010:  ffff ffff e28d 2711 00c1 9ee1 0206 00b5  ......'.........              
    0x0020:  0200 0ad0 21f9 5cfe 67c0 a801 6c01 0006  ....!.\.g...l...              
    0x0030:  d021 f95c fe67 0a00 0400 0d0a 310b 0005  .!.\.g......1...              
    0x0040:  5536 2d4c 520c 0007 5541 4c52 3676 3203  U6-LR...UALR6v2.              
    0x0050:  0022 425a 2e4d 5437 3632 325f 362e 302e  ."BZ.MT7622_6.0.              
    0x0060:  3231 2b31 3336 3733 2e32 3230 3630 372e  21+13673.220607.              
    0x0070:  3230 3034 1600 0c36 2e30 2e32 312e 3133  2004...6.0.21.13              
    0x0080:  3637 3315 0007 5541 4c52 3676 3217 0001  673...UALR6v2...              
    0x0090:  0018 0001 0019 0001 011a 0001 0113 0006  ................              
    0x00a0:  d021 f95c fe67 1200 0400 029b 511b 0007  .!.\.g......Q...              
    0x00b0:  352e 3433 2e33 3727 0008 1e4d e602 d8c7  5.43.37'...M....              
    0x00c0:  e465 2a00 1065 1358 cd13 2849 318e 4de6  .e*..e.X..(I1.M.              
    0x00d0:  02d8 c7e4 65                             ....e                         
    Date=2022-08-01 Time=10:29:38 log_id=0103021 log_type=Firewall log_component=Loc
    al_ACLs log_subtype=Denied log_status=N/A log_priority=Alert duration=N/A in_dev
    =Port2 out_dev= inzone_id=2 outzone_id=4 source_mac=d0:21:f9:5c:fe:67 dest_mac=f
    f:ff:ff:ff:ff:ff bridge_name= l3_protocol=IPv4 source_ip=192.168.1.108 dest_ip=2
    55.255.255.255 l4_protocol=UDP source_port=57997 dest_port=10001 fw_rule_id=N/A 
    policytype=0 live_userid=0 userid=0 user_gp=0 ips_id=0 sslvpn_id=0 web_filter_id
    =0 hotspot_id=0 hotspotuser_id=0 hb_src=0 hb_dst=0 dnat_done=0 icap_id=0 app_fil
    ter_id=0 app_category_id=0 app_id=0 category_id=0 bandwidth_id=0 up_classid=0 dn
    _classid=0 nat_id=0 cluster_node=0 inmark=0x8001 nfqueue=0 gateway_offset=0 conn
    id=1454646528 masterid=0 status=256 state=0, flag0=549757911040 flags1=0 pbdid_d
    ir0=0 pbrid_dir1=0 

  • Conntrack established is fine, and we can see the FW rule id is 5 from where the traffic passes and the natid is 1, can you confirm whether it is correct a correct rule or not ?
    drop traffic is mainly cause of the ACL component  and the destination port differs from the conntrack captured so seems not relevant !! 

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Technical Account Manager 3 | Cyber Security Evolved


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.