Any/Any rule still showing Violation in packet capture

What did I do wrong?



Added TAGs
[edited by: Raphael Alganes at 3:23 PM (GMT -7) on 18 Apr 2024]
Parents
  • Hi  ,

    Thank you for reaching out to the community, may we know the reason to add an any to any rule instead of a well defined zone to zone rule ?
    REF - Add a NAT rule

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 

    Log a Support Case | Sophos Service Guide
    Best Practices – Support Case


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • It was part of my attempt to create a more well defined zone to zone rule. I am not familiar with the VoIP system, inherited it from another MSP. I am replacing an old Sonicwall with a Sophos and these phones were not connecting. The Phone server is on another vlan. Added the any/any and they connected, so I was looking at packet capture to narrow down what that well defined zone to zone rule needed. When I added the new rules and turned off the any/any, the phones disconnected again. I turned off the new rules and renabled the any/any and the phone was still getting blocked. 

    I had to call into support, and after they did some troubleshooting they had to do some back end stuff using SSH to fix it. 

    Problem statement

    • Facing issues in VLAN communication. 

    Steps Taken

    • We checked that you were not able to connect to the PBX server which is behind the VLAN1:100.
    • SRC IP: 192.168.20.206 and PBX IP: 10.100.3.124
    • We could see the GUI PCAP and in that, it's showing the violation and the reason is FIrewall.
    • We also checked the drop and tcpdump and in the tcpdump, we can see that the traffic forwarding fro VLAN 1:20 to VLAN 1:100 but we were not receiving any response.
    • We flush the conntrack for the DST IP.
    • After flushing the conntrack now PBX server is reachable and working fine.

    It is definetly frustrating that it would take something like this to fix the problem. How would someone like me who has not studied and mastered the CLI be able to figure this out? If I turn off or delete a rule using the GUI, I expect it to be turned off or deleted. The fact that any/any was still blocking something from a deleted rule is crazy. 

    Sorry for the rant. 

  • Hi,

    if a device has an established connection, then disabling or deleting the rule will not drop the connection, this is from previous posts on similar subjects.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • I reset the phone several times while troubleshooting, not sure that is considered a reset of the connection.

Reply Children