This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

The firewall blocks all ports from DNAT rules except ports 80 and 443

Hi All,

The firewall blocks all ports from DNAT rules except ports 80 and 443. I had a DNAT rule for NAT public service with custom port 8081, in the NAT rule I set the Intrusion prevention WAN to LAN. Of course, it runs for a long time with no error.

Today, our client reports that they cannot access the public service with port 8081 by the web browser, can access it by telnet to 8081, so the NAT rule is not abnormal.

I tried to change the port from 8081 to 8089 but no result.

I tried to make Intrusion prevention to None in the NAT rule then our client can access to service with port 8081 normally.

I have check Backup and Firmware/Pattern Updates found that IPS and Application signatures updated 06:45:20, Nov 15, 2019, and the version is 9.16.45. I think it is a root cause.

I wonder why the Intrusion Prevention System (IPS) blocks all the ports except 80/443?
So how to make an exception for NAT rule?

Thanks

 

My product:

XG310 (SFOS 17.5.8 MR-8)



This thread was automatically locked due to age.