This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Basic Firewall Question

Hello.

I cannot wrap my head around this very basic issue.
I have configured 2 firewall rules in the UTM:

position --          source  --       service  --      action --   destination
1      --              x.x.x.61  --     any      --       reject --   any
2      --              any     --        websurf  --     allow  --    any

Why can this host 61 still surf the internet? In my understanding the 1st rule will be applied and the second will be ignored for host 61.

Any advice is apprciated.

Best regards,
Stefan


This thread was automatically locked due to age.
Parents
  • Hi Stefan and welcome at the Sophos User BB! [:)]

    As William stated you most likely do have Web Protection tirned on, so the web traffic will never hit the firewall.
    Also check out BAlfson's Rulz, where you can find more information.

    To entirely block this host you can DNAT it to a non-existent address.

    ----------
    Sophos user, admin and reseller.
    Private Setup:

    • XG: HPE DL20 Gen9 (Core i3-7300, 8GB RAM, 120GB SSD) | XG 18.0 (Home License) with: Web Protection, Site-to-Site-VPN (IPSec, RED-Tunnel), Remote Access (SSL, HTML5)
    • UTM: 2 vCPUs, 2GB RAM, 50GB vHDD, 2 vNICs on vServer (KVM) | UTM 9.7 (Home License) with: Email Protection, Webserver Protection, RED-Tunnel (server)
Reply
  • Hi Stefan and welcome at the Sophos User BB! [:)]

    As William stated you most likely do have Web Protection tirned on, so the web traffic will never hit the firewall.
    Also check out BAlfson's Rulz, where you can find more information.

    To entirely block this host you can DNAT it to a non-existent address.

    ----------
    Sophos user, admin and reseller.
    Private Setup:

    • XG: HPE DL20 Gen9 (Core i3-7300, 8GB RAM, 120GB SSD) | XG 18.0 (Home License) with: Web Protection, Site-to-Site-VPN (IPSec, RED-Tunnel), Remote Access (SSL, HTML5)
    • UTM: 2 vCPUs, 2GB RAM, 50GB vHDD, 2 vNICs on vServer (KVM) | UTM 9.7 (Home License) with: Email Protection, Webserver Protection, RED-Tunnel (server)
Children
No Data