This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Clean Up rule "from any, to any, drop" that's allowed on the Internet anyway !!! WTF ?

Hello  Can anyone explain that to me ?

I have a clean up rule (no 3) "from any, to any, drop" that allows traffic on the Internet anyway !!!.  See the rule and the log below.

Is it me, or this is a very serious issue ?



This thread was automatically locked due to age.
Parents
  • Hi,

    this not a serious issue. Where does this rule sit in the firewall rule list and what is its ID eg at the top. Why are you trying to block all internet access, this does not make sense?

    What you are seeing in your log is traffic going out another rule eg rule id 3.

    XG tests the packets from top down, not by rule number.

    Ian

  • Hello 

    Best practices guidelines for "serious" world-class firewall products requires the implementation of a least one "stealth" rule and one "clean up" rule.  By definition, a "clean up" rule is always the last ... It does what it says: drop everything that was not implemented on previous rules and logs it.

     

    So, by definition, nothing is allowed by this rule, or after this rule !!!  Yet, we see some traffic is allowed.

     

    My understanding here, is that's, on the contrary, an awful issue.

Reply
  • Hello 

    Best practices guidelines for "serious" world-class firewall products requires the implementation of a least one "stealth" rule and one "clean up" rule.  By definition, a "clean up" rule is always the last ... It does what it says: drop everything that was not implemented on previous rules and logs it.

     

    So, by definition, nothing is allowed by this rule, or after this rule !!!  Yet, we see some traffic is allowed.

     

    My understanding here, is that's, on the contrary, an awful issue.

Children