<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Network Protection Firewall Violations - Where am I going wrong and how to fix</title><link>https://community.sophos.com/utm-firewall/f/management-networking-logging-and-reporting/131554/network-protection-firewall-violations---where-am-i-going-wrong-and-how-to-fix</link><description>Still at lowest end of learning curve and have found that I am getting 80+ firewall violations reported daily and 0 prevention statistics. 
 I am very concerned that I have something wrong with my protection and seek help in identifying where to look</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Network Protection Firewall Violations - Where am I going wrong and how to fix</title><link>https://community.sophos.com/thread/483744?ContentTypeID=1</link><pubDate>Sat, 04 Dec 2021 17:58:56 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:6207b032-e54e-4db0-96b9-ff56419ad1d6</guid><dc:creator>Budgie2</dc:creator><description>&lt;p&gt;Many thanks to both Dirk and Amodin for putting my mind at rest.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;I do had one minor problem with the second WAN connection as the configuration options which Dirk linked me to are not quite as I find on the UTM.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Rather than set the second WAN connection as a fallback if my main connection fails I have set the percentage 90% to 10% between primary and secondary connection and will see how I get on.&amp;nbsp; May need to tweak a bit.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Meanwhile my thanks to all,&lt;/p&gt;
&lt;p&gt;Budge.&amp;nbsp; &amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Network Protection Firewall Violations - Where am I going wrong and how to fix</title><link>https://community.sophos.com/thread/483743?ContentTypeID=1</link><pubDate>Sat, 04 Dec 2021 17:19:41 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:ad9c6312-363d-4a27-898b-3e52214bb766</guid><dc:creator>Amodin</dc:creator><description>&lt;p&gt;This is normal and showing you the UTM is doing its job.&amp;nbsp;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Network Protection Firewall Violations - Where am I going wrong and how to fix</title><link>https://community.sophos.com/thread/483737?ContentTypeID=1</link><pubDate>Sat, 04 Dec 2021 16:18:26 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:cdc97c59-9b45-4c3d-b101-8b2987823145</guid><dc:creator>dirkkotte</dc:creator><description>&lt;p&gt;Firewall-violations are ok.&lt;/p&gt;
&lt;p&gt;Here are all packets counted, you don&amp;#39;t allow passing the firewall.&lt;/p&gt;
&lt;p&gt;Even if you use an &amp;quot;any - any - any&amp;quot; rule you will see/count dropped packets. These may be broadcasts or packets directed to interface-IP of the firewall.&lt;/p&gt;
&lt;p&gt;if your services are available .. without problems ... you can ignore the dropped packets / Firewall-violations (we have multiple hundred per minute at the company)&lt;/p&gt;
&lt;p&gt;You can open the firewall-live-log and take a look to the allowed/dropped packets. You may post these logs if there are questions.&lt;/p&gt;
&lt;p&gt;PS: IPS-violations = 0&amp;nbsp; is good too.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Network Protection Firewall Violations - Where am I going wrong and how to fix</title><link>https://community.sophos.com/thread/483730?ContentTypeID=1</link><pubDate>Sat, 04 Dec 2021 10:20:07 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:aa23f67c-37c0-48db-af19-fd296abfad7e</guid><dc:creator>Budgie2</dc:creator><description>&lt;p&gt;Hi and thanks for the reply.&lt;/p&gt;
&lt;p&gt;The screenshot is what is worrying me and I have no idea where the problem lies.&lt;/p&gt;
&lt;p&gt;I can copy and past log but I shall need some guidance on which log please&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/53/pastedimage1638612959029v1.png" alt=" " /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Network Protection Firewall Violations - Where am I going wrong and how to fix</title><link>https://community.sophos.com/thread/483717?ContentTypeID=1</link><pubDate>Fri, 03 Dec 2021 20:18:26 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:7d49846b-7826-4186-a71b-009a101b9e0b</guid><dc:creator>Amodin</dc:creator><description>&lt;p&gt;I don&amp;#39;t really understand what you are asking about/concerned about.&amp;nbsp; Are you seeing IPS violations, dropped destination/source hosts and thinking this is an issue?&amp;nbsp; Is it web traffic being blocked/reported?&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Can you copy/paste the log in which you are referring, and/or click and drag a screenshot into the reply window so we can see what you are specifically referring to?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>