Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

An allow firewall rule creating many denied logs, drppkt shows nothing

I notice many firewall denied firewall logs created by a rule, that is an allow rule only.

Even more strange is, that the port 1027 logged is not contained in the rule.

Watching the traffic with drppkt shows no blocked packets.

Tcpdump shows the packets on CLI and WUI

I think I need some help to  understand what is happening here.

That is the  log:

And the the Firewall Rule:

WUI tcpdump:

cli tcpdump

Fullscreen
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
17:37:39.583731 lag0, IN: IP 172.xxx.xxx.241.56228 > 172.xxx.xxx.135.1027: Flags [.], ack 458, win 63784, length 0
17:37:39.583744 lag0.25, OUT: IP 172.xxx.xxx.241.56228 > 172.xxx.xxx.135.1027: Flags [.], ack 458, win 63784, length 0
17:37:39.583745 lag0, OUT: ethertype IPv4, IP 172.xxx.xxx.241.56228 > 172.xxx.xxx.135.1027: Flags [.], ack 458, win 63784, length 0
17:37:39.583745 PortA3, OUT: ethertype IPv4, IP 172.xxx.xxx.241.56228 > 172.xxx.xxx.135.1027: Flags [.], ack 458, win 63784, length 0
17:37:39.796507 PortA3, IN: IP 172.xxx.xxx.241.56229 > 172.xxx.xxx.135.1027: Flags [S], seq 1846860113, win 8192, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
17:37:39.796507 lag0, IN: IP 172.xxx.xxx.241.56229 > 172.xxx.xxx.135.1027: Flags [S], seq 1846860113, win 8192, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
17:37:39.796578 lag0.25, OUT: IP 172.xxx.xxx.241.56229 > 172.xxx.xxx.135.1027: Flags [S], seq 1846860113, win 8192, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
17:37:39.796581 lag0, OUT: ethertype IPv4, IP 172.xxx.xxx.241.56229 > 172.xxx.xxx.135.1027: Flags [S], seq 1846860113, win 8192, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
17:37:39.796582 PortA3, OUT: ethertype IPv4, IP 172.xxx.xxx.241.56229 > 172.xxx.xxx.135.1027: Flags [S], seq 1846860113, win 8192, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
17:37:39.796659 PortA3, IN: ethertype IPv4, IP 172.xxx.xxx.135.1027 > 172.xxx.xxx.241.56229: Flags [S.], seq 0, ack 1846860114, win 1460, options [mss 1460], length 0
17:37:39.796659 lag0, IN: ethertype IPv4, IP 172.xxx.xxx.135.1027 > 172.xxx.xxx.241.56229: Flags [S.], seq 0, ack 1846860114, win 1460, options [mss 1460], length 0
17:37:39.796659 lag0.25, IN: IP 172.xxx.xxx.135.1027 > 172.xxx.xxx.241.56229: Flags [S.], seq 0, ack 1846860114, win 1460, options [mss 1460], length 0
17:37:39.796697 lag0, OUT: IP 172.xxx.xxx.135.1027 > 172.xxx.xxx.241.56229: Flags [S.], seq 0, ack 1846860114, win 1460, options [mss 1460], length 0
17:37:39.796699 PortA3, OUT: IP 172.xxx.xxx.135.1027 > 172.xxx.xxx.241.56229: Flags [S.], seq 0, ack 1846860114, win 1460, options [mss 1460], length 0
17:37:39.796864 PortA3, IN: IP 172.xxx.xxx.241.56229 > 172.xxx.xxx.135.1027: Flags [.], ack 1, win 64240, length 0
17:37:39.796864 lag0, IN: IP 172.xxx.xxx.241.56229 > 172.xxx.xxx.135.1027: Flags [.], ack 1, win 64240, length 0
17:37:39.796898 lag0.25, OUT: IP 172.xxx.xxx.241.56229 > 172.xxx.xxx.135.1027: Flags [.], ack 1, win 64240, length 0
17:37:39.796900 lag0, OUT: ethertype IPv4, IP 172.xxx.xxx.241.56229 > 172.xxx.xxx.135.1027: Flags [.], ack 1, win 64240, length 0
17:37:39.796901 PortA3, OUT: ethertype IPv4, IP 172.xxx.xxx.241.56229 > 172.xxx.xxx.135.1027: Flags [.], ack 1, win 64240, length 0
17:37:39.797710 PortA3, IN: ethertype IPv4, IP 172.xxx.xxx.135.1027 > 172.xxx.xxx.241.56229: Flags [P.], seq 1:457, ack 1, win 1460, length 456
17:37:39.797710 lag0, IN: ethertype IPv4, IP 172.xxx.xxx.135.1027 > 172.xxx.xxx.241.56229: Flags [P.], seq 1:457, ack 1, win 1460, length 456
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

drppkt: nothing



This thread was automatically locked due to age.
x An error occurred. Please try again or contact your administrator.