My testbox wants to drive me nuts.
I got a rule here for some web chatting application where i allowed some ports (Service group) from internal outgoing to any.
Yeah i know thats not urgent [;)] but could get ugly if i'm right...
Well anyway my box drops one port of this group with the nice comment "autogenerated rule"
I already
- deactivated any NAT rules with auto filter generation
- replaced my own definition for my net with the autogenerated definition of my internal interface
- changed from group to 4 single service rules
- just for paranoia deactivated the whole IPS
- set the rule on top of my filters
- double checked all definitions related to this
- retryed with same config on 7.104 (still working as it should)
My suggestion is first of all that the autorules have a higher priority than the selfmade ones.
well anyway i dont even know where that rule comes from but its there.
perhaps someone has an idea what to look for.
Auto-generated rule TCP 192.168.XX.YYY:1907 → 1.2.3.4:5222 [ACKPSH ] len=184 ttl=127 tos=0x00
While searching for this i notice that QoS jumped from Net. Sec. to Network.
and why are there 24 default "traffic Selectors" that i can't delete nor edit?
I would say i should be able, to since i wont ever need that ones.
somebody wants to retry or has some common problems?
send an PN if you want i'll tell you site and packet filter rule then.
Cheers and an nice weekend
Daniel
---edit
got it... see reply 4 please