What did I do wrong?
Added TAGs
[edited by: Raphael Alganes at 3:23 PM (GMT -7) on 18 Apr 2024]
What did I do wrong?
Hi Ben Woolley ,
Thank you for reaching out to the community, may we know the reason to add an any to any rule instead of a well defined zone to zone rule ?
REF - Add a NAT rule
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Global Support & Services
Log a Support Case | Sophos Service Guide
Best Practices – Support Case
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
It was part of my attempt to create a more well defined zone to zone rule. I am not familiar with the VoIP system, inherited it from another MSP. I am replacing an old Sonicwall with a Sophos and these phones were not connecting. The Phone server is on another vlan. Added the any/any and they connected, so I was looking at packet capture to narrow down what that well defined zone to zone rule needed. When I added the new rules and turned off the any/any, the phones disconnected again. I turned off the new rules and renabled the any/any and the phone was still getting blocked.
I had to call into support, and after they did some troubleshooting they had to do some back end stuff using SSH to fix it.
Problem statement
Steps Taken
It is definetly frustrating that it would take something like this to fix the problem. How would someone like me who has not studied and mastered the CLI be able to figure this out? If I turn off or delete a rule using the GUI, I expect it to be turned off or deleted. The fact that any/any was still blocking something from a deleted rule is crazy.
Sorry for the rant.
Hi,
if a device has an established connection, then disabling or deleting the rule will not drop the connection, this is from previous posts on similar subjects.
Ian
XG115W - v20 GA - Home
XG on VM 8 - v20 GA
If a post solves your question please use the 'Verify Answer' button.
I reset the phone several times while troubleshooting, not sure that is considered a reset of the connection.
__________________________________________________________________________________________________________________
Thanks for that, but I think you are still missing the point of my question. It was not specifically about VoIP behaving badly, but the fact that an ANY/ANY rule was still blocking traffic.
Thanks for that, but I think you are still missing the point of my question. It was not specifically about VoIP behaving badly, but the fact that an ANY/ANY rule was still blocking traffic.