Clean-Up / Drop-All rule still fails to work properly.

A pictures says it all.  Rule 10.  On top, the firewall rules clearly says to drop.  At the bottom, the log clearly says accepted.  And yet 0 Bytes is recorded on the firewall rule.  That's so regrettable.

Paul Jr

Parents
  • Hello Paul,

    do you really see this behaviour on 17.x?

    I am using a similar rule on SFOS 17.5 MR7 and it works (drops packets, writes corresponding log entry).

    Best regards,
    Bernd

  • Yes everywhere on any machine.

    The same firewall rule on an XG210rev3 running v17.5.8

    You see this ???

    Firewall rule 21 should clearly "drop", yet the log viewer show "accepted".  Who I'm I supposed to believe ???  This is a firewall Jesus !!!  It's no device one should assume something is while the device says it's not !!!  It has been like this for years now !!!  Firewall 101 has to be more serious than that !!!

    Paul Jr

  • I may be able to explain the Rootcause for this behavior.

    Maybe you notice, a drop rule will also load the proxy for this traffic. (The yellow "WEB" is in every drop rule).

    All "green" rules are basically web traffic, because the firewall ruleset will properly give this traffic to proxy to drop it via proxy. 

    So in case of the firewall rule set, its a "allowed" traffic but the proxy will deny it. 

     

    Thats my observation. 

    __________________________________________________________________________________________________________________

Reply
  • I may be able to explain the Rootcause for this behavior.

    Maybe you notice, a drop rule will also load the proxy for this traffic. (The yellow "WEB" is in every drop rule).

    All "green" rules are basically web traffic, because the firewall ruleset will properly give this traffic to proxy to drop it via proxy. 

    So in case of the firewall rule set, its a "allowed" traffic but the proxy will deny it. 

     

    Thats my observation. 

    __________________________________________________________________________________________________________________

Children