Skip to main content
pnobels
New Member
December 5, 2024
Solved

APP_FILTER blocking connection altough category set to monitor

  • December 5, 2024
  • 3 replies
  • 1105 views

Hi,

 

noticed something unexpected today.

 

Internet access for specific host is blocked based on app filter.  When checking the UTM blocked rule i see it's actually blocked because of :

 

Screenshot 2024-12-05 160753.png

 

However, when viewing the APP_FILTER cloud.IT is only set to monitor : 

 

Screenshot 2024-12-05 161415.png

Could be blocked on one of the overrides, but i see no further info in the Analyzer logs on which override.

Is there any way to debug this further?

 

Best answer by pminarik

While Cloud.IT is set to monitor, your override rule #5 says to block Botnet, Evasive, and Tunneling. ForcePoint.Cloud.Proxy matches this with the Tunneling flag.

3 replies

sjoshi
Staff
Staff
December 5, 2024

is that host using proxy to connect internet?

Thanks, Salon
pnobels
pnobelsAuthor
New Member
December 6, 2024

no proxy is used

sjoshi
Staff
Staff
December 6, 2024

it is being blocked by force point cloud proxy

can you allow that app signature and put it on top under app override rule

Thanks, Salon
pnobels
pnobelsAuthor
New Member
December 9, 2024

It works by allowing the forcepoint cloud proxy app signature as an override.  But does not explain why it's blocked originally since cloud.IT is set to monitor only... 

pminarik
Staff
pminarikAnswer
Staff
December 9, 2024

While Cloud.IT is set to monitor, your override rule #5 says to block Botnet, Evasive, and Tunneling. ForcePoint.Cloud.Proxy matches this with the Tunneling flag.