Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

"Drop" vs "Reject" HTTP + HTTPS messages

Hello, in Sophos XG firewalls, what is the difference between "drop" and "reject"?  My understanding is that when you drop it simply and silently drops the packets without any response to the requesting device.  "Reject" would on the other hand send a message specifying the reject of the packet request.  We were testing dropping traffic via specified country and we noticed that it claimed there was tons of "outgoing" traffic on the rule where we geo blocked.  It was about 89 gigs worth which seems remarkably high for having "drop" as the action.  Is this somehow sending a message to the client anyway even though we have it set to drop? It isn't sending any sort of "this site is blocked due to policy" web page to them is it?



This thread was automatically locked due to age.
Parents
  • The Webpage will be removed in a future V18 Release. So the Block Rule will actually block http/s traffic. Currently the proxy will take care of the blocking. This means the packet exchange could be more then simply drop. 

    NC-64820 for references. 

Reply
  • The Webpage will be removed in a future V18 Release. So the Block Rule will actually block http/s traffic. Currently the proxy will take care of the blocking. This means the packet exchange could be more then simply drop. 

    NC-64820 for references. 

Children