This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Traffic allowed although policy test says 'blocked'

Hello All,

I'm having a weird problem here. I want to block a server completely from accessing the internet. What I've done:

- Created a firewall rule that blocks all traffic. Checked it, works for any port except FTP/HTTP/HTTPS (as expected, as I do have web filtering enabled)

- Added a 'block all' web filtering policy for this host

- Did a policy check for this hosts' IP to, say, www.dlr.de -> Result blocked, so OK!

- Did a 'wget www.dlr.de' from the host itself - works, so NOT OK?!?

- Turn off web filtering

- Did a 'wget www.dlr.de' from the host itself - doesn't work any more

So it's definitely web filtering, but policy check everything is fine. Can anybody sched some light on what might be going wrong here?

Thank you,

   Jörg



This thread was automatically locked due to age.
Parents
  • Hallo Jörg and welcome to the UTM Community!

    You found your problem, I see.  You still might be interested in #2 in Rulz (last updated 2019-04-17) for solving similar problems in the future.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hello Bob,

    thank you. Yes, I already did that - it doesn't menition the transparent skip list, though. It would also be nice, if the 'policy check' would check against this list explicitly. It would have saved me some headache ;-)

    Regards,

        Jörg

Reply
  • Hello Bob,

    thank you. Yes, I already did that - it doesn't menition the transparent skip list, though. It would also be nice, if the 'policy check' would check against this list explicitly. It would have saved me some headache ;-)

    Regards,

        Jörg

Children
No Data