This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Drop Package


We have DNAT rule that allow connection over port 443 to an internal server, I have enable loging for this DNAT rule because we have some complaints that some users sometimes cannot access the internal server. I did check the FW logs and could see this entry:


017:06:20-10:22:40 securitysrv1-1 ulogd[26092]: id="2001" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped" action="drop" fwrule="60001" initf="eth0" srcmac="14:e0:39:06:76:9a" dstmac="00:1a:9c:f1:1f:a0" srcip="95.XX.XX.36" dstip="62.XX.XX.193" proto="6" length="40" tos="0x00" prec="0x00" ttl="56" srcport="58955" dstport="443" tcpflags="RST"

There is a rule that allow connection to the internal server, becuase I can access the internal server no problem there, but why UTM reset the connection?



This thread was automatically locked due to age.