Hello,
In our scenario there is an XG with a Primary Internet and a Backup Internet (Using an external LTE router on Port 3) connections configured on WAN link manager.
We are trying to block all traffic except to a credit card provider when on the Backup LTE connection since is metered. Seems like we still have some traffic going thru the LTE Backup connection that we suspect is from CFM or patterns update to the XG (Unless you see any error on our configuration that is allowing more LAN traffic). Any idea on how to allow SOPHOS CFM and updates only when/thru the primary Internet connection is up.
Configuration
(1st Rule) Credit Card Firewall Rule:
Source Zone: LAN Source Networks: Any
Destination Zone: WAN Destination Networks: Credit Card Company Services: Any
Web Policy: Credit Card Policy
Policy: Allow: Custom Category of the Credit Card Company
Default Action: Deny
Application Control: Deny All
Primary Gateway: WAN Link Load Balance
(2nd Rule) Office to Internet Firewall Rule:
Source Zone: LAN Source Networks: Any
Destination Zone: WAN Destination Networks: Any Services: Any
Web Policy: Office Policy
Policy: Allow: Some categories allowed
Default Action: Deny
Application Control: Deny All
Primary Gateway: Primary_Connection
All Web - Exceptions are disabled.
Thank you
This thread was automatically locked due to age.