This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall rule does not work as expected

Hello,

I'm really not new to the XG system, but right now I got no clue what's going on.
I defined a firewall rule (Test) in my 'exeptions' group. The rule ID is #2:

The destination is a FQDN-hostgroup "Origin" with several FQDN-hosts associated:

The "IP-collector" for the domain "ea.com" for example, works flawless and it collects all the associated IPs automatically:

But when I now start a origin game like "BFV" the "Test" rule (#2) will not be triggered like expected. Instead of the Test rule, the rule with ID6 is triggered:

As you can see, this is a rule I defined under the "Web-Filter" group. It's my HTTPS-scanning rule.

BTW: I use the DPI engine instead of proxy and already defined exeptions for the domains "ea.com" etc. destinations...

What I am doing wrong? Maybe it's really something simple I don't see right now... Confused

Thank you.



This thread was automatically locked due to age.

Top Replies

  • This is the usual behavior if you're relying on FQDN for Firewall rules. (It's a bit unreliable)

    One other thing, using a full domain is much more reliable than wildcards on XG for FQDN's. (This is from personal experience while dealing with SD-WAN.)

    If you want to bypass Origin traffic from being scanned or decrypted then it's much better to use the Web Exceptions than creating a Firewall Rule with FQDN's.

    Also, what issues you're currently having with Origin and Battlelog? I'm doing TLS Inspection (Decryption) and still managed to (login) play BF4 and BF5 as expected. (Even with Proton on Steam)

    Jump to answer
Parents Reply Children
  • Yes. I use two certificates. One for the SSL scanning itself and the "web admin certificate" for the user portal because i use the DPI engine and application control.
    In the past i could reproduce an error during the EAP phase for v18. When the connection got intermitted for scanning, i got an certificate error until i defined a web admin certificate with alternate name and then rolled it out on the client. Since then it works flawless.
    But i guess this a antoher story. Grin