This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Any-Any-Any still dropping packets UTM 9.501-5

I'm completely mystified. User complains about the login component of this page 

https://www.ticketmaster.ca/member?tm_link=tm_homeA_header_my_account

will not load. Switching networks (e.g. to wireless that does not pass through the UTM) loads fine.

The firewall log shows what is pasted below. I know that 60002 means some kind of outgoing rule is missing, (probably same for that 60003 rule) but even adding an ANY>ANY>ANY rule doesn't eliminate that. Looking through past posts for awhile and disabling pretty much every security feature these is, still, no login box. 

I'm very rusty with this and I'm looking for some help as to what my next step should be here. I just want this website to load, and I suspect that other sites are also affected by this. 

Appreciate any help!

2018:06:17-08:33:41 remote ulogd[4541]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" initf="eth1" outitf="eth1" srcmac="00:01:5c:9b:b6:46" dstmac="00:1a:8c:42:69:55" srcip="185.208.208.77" dstip="174.2.181.145" proto="6" length="40" tos="0x00" prec="0x00" ttl="240" srcport="57934" dstport="35027" tcpflags="SYN" 

2018:06:17-08:34:43 remote ulogd[4541]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60002" initf="eth1" outitf="eth1" srcmac="00:01:5c:9b:b6:46" dstmac="00:1a:8c:42:69:55" srcip="5.141.82.192" dstip="174.2.181.145" proto="6" length="40" tos="0x00" prec="0x00" ttl="52" srcport="61155" dstport="2323" tcpflags="SYN" 

2018:06:17-08:46:17 remote ulogd[4541]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60003" outitf="eth1" srcmac="00:1a:8c:42:69:55" srcip="184.11.11.178" dstip="218.102.239.14" proto="1" length="68" tos="0x00" prec="0xc0" ttl="64" type="11" code="0" 



This thread was automatically locked due to age.
Parents
  • Do you have an allow-outgoing rule in your firewall ruleset?

    Why are you not using web filtering?  It is UTMs best asset.

  • I'm just trying to eliminate any potential culprits. I set this thing up over a year ago, and while it took some work (I recall getting the VPN going was a pain) it has mostly been working correctly. It seems like there have been weird little issues off and on ever since the switch to a new ISP (new IP) even though I changed the static in settings. 

     

    I am tempted to revert to factory settings and start from scratch. 

Reply
  • I'm just trying to eliminate any potential culprits. I set this thing up over a year ago, and while it took some work (I recall getting the VPN going was a pain) it has mostly been working correctly. It seems like there have been weird little issues off and on ever since the switch to a new ISP (new IP) even though I changed the static in settings. 

     

    I am tempted to revert to factory settings and start from scratch. 

Children
No Data