Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

UTM 9.6 Firewall not dropping incoming

I`m facing issue with firewall its not dropping specified traffic as defined in rules. Just for info web protection is completely turned off.

E.g

Traffic from google.com->ANY->internal->drop

This rule is on #1 in firewall rules but still able to access google or see ads by google ads. I`ve defined Fqdn in dns group and its fetching all ip`s related to google. I`ve also got a rule #2 to drop tafficfactory.com using Fqdn but still no luck. Fqdn is working pretty well without any issue. If i block traffic from internal->trafficfactory.com->External it does work but again its outbound. Firewall logs shows all traffic as internal ip -> public ip and src/dst MAC. I`m out of options here how to drop all inbound from trafficfactory.com.

in the image below you can see that logs only show outbound no inbound means public ip->private ip

Image below shows drop rule. Let me know if something is wrong



This thread was automatically locked due to age.
Parents Reply Children
No Data