This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

1st Firewall rule has GEO blocks. But I am seeing this rule cause ALLOWS in the log. What is going on?

Hello,

I guess I am confused about the new V18 firewall rules and NAT etc.

I really expect my Firewall rules to be the 1st line of defense against the Internet bad guys.  So I put as my 1st rule country blocks to keep my network safe.

Much of the traffic is blocked.  But in the LOG I am seeing this rule ALLOW some traffic.

I also see there is a Web rule ID.

Can someone explain why this traffic is getting through when the firewall rule says to block it.

Thank You,

Peter Geremia



This thread was automatically locked due to age.
Parents
  • Looks like the Proxy is picking up this traffic and blocking it.

    As you can see, the Block rule has the Proxy enabled, hence Firewall will give the traffic to the proxy to drop it. You can see the destination port transferred to Port 3128 (proxy). 

    The traffic should not be actually allowed, as the proxy will drop it anyways. But the log viewer will show this as "allowed". 

Reply
  • Looks like the Proxy is picking up this traffic and blocking it.

    As you can see, the Block rule has the Proxy enabled, hence Firewall will give the traffic to the proxy to drop it. You can see the destination port transferred to Port 3128 (proxy). 

    The traffic should not be actually allowed, as the proxy will drop it anyways. But the log viewer will show this as "allowed". 

Children