This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Cannot block traffic

I am trying to find out why traffic is being allowed to a newly created dmz when there are no rules to allow it and there are rules blocking it. All of my rules are specific from one zone to the internet. At the bottom of my rule list is a block any - any - any rule. I am able to ping in both directions and a port scan shows I have full access despite the block. I have verified there are no allow any rules above the drop rule. There is nothing logged when I ping a server in the dmz. What else can I do to enforce the block rule. I have run into this frequently on this firewall where I will set an explicit deny rule and it has no effect. Example is I set one computer to be denied from accessing internet outside of certain hours. It has no effect on access even though it is at the top of the list.

Please help.



This thread was automatically locked due to age.
Parents
  • Hello,

    Also be aware that if you are using web filtering, that you will need to explicitly deny access between subnets in the web filtering config, otherwise you will still be able to access services behind the proxy.


    Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

    Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.

  • Yes, check #2 in Rulz, BC.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply Children
No Data