Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Application Filter - Source and Destination IP mismatch?

Hi,

I'd think source and destination IP is wrong here.

It took me some time to help a user who reported he cannot download a file, we blocked because I could not find his computer with my query for source IP.

We block executabled here.

Other Application filter blocks look OK, eg. accessing blocked applications:



This thread was automatically locked due to age.
Parents Reply Children
  • Blocked does not mean, we are terminate the connection. This means the server will still ddos you with the packets, as the server assume, you simply does not ACK them. TCP makes sure, you ACK each and every packet. The client cannot ACK a packet, which does not reach him, as the firewall blocks it. Therefore the Server assume, you did not get the packet. It will retransmission those packets all the time, resulting into a big junk of data before the server finally realize, there is nobody to ACK the packets. 

  • Block or deny should mean the application does not leave the XG, does not advertise itself or your network to the world and leave your XG and network open to security attacks. The aim is to reduce the size of the exposure footprint to the world.

    If the packets can be identified and blocked on the way in then the same rules should applied to the packets on the way out.

    Maybe I am taking a too simplistic approach to application security?

    Ian