Skip to main content
frax
New Member
January 26, 2017
Question

Bypassed firewall rule

  • January 26, 2017
  • 8 replies
  • 10243 views

Hello, today I noticed a strange behavior of my firewall, I have the following rules:

 

edit 1 set srcintf "INT" set dstintf "WAN" set srcaddr "LocalIP" set dstaddr "all" set action accept set schedule "always" set service "HTTP" set utm-status enable set av-profile "Standard" set webfilter-profile "AllowedDomain" <------- the webfilter is configured like proxy and there are only some domains  set ips-sensor "protect_client" set application-list "Everyone" set profile-protocol-options "default" set ssl-ssh-profile "deep-inspection" set nat enable

 

edit 2

edit 48 set srcintf "INT" set dstintf "WAN" set srcaddr "LocalIP" set dstaddr "all" set action deny

 

Configuring several IP cameras I realized that the devices comunicated with external servers that were not included in the webfilter, how is it possible? The webfilter shouldn't filter out the request?

 

Regards

Frencky

 

    8 replies

    rwpatterson
    New Member
    January 26, 2017

    What is the order of the rules? First good one from top-down gets the traffic.

    tanr
    New Member
    January 27, 2017

    Your policy 1 is set to only work with service HTTP, so any non HTTP communication won't match it.

     

    If you do have other policies covering all the other services with the same web filter, then we'd have to dig a little deeper:

    - Are there any devices that aren't on the "INT" interface?

    - Any devices that have IPs not in the LocalIP range?

    - Any other routes out other than through the "WAN" interface?

    - Do you have logs showing the access of external servers?  

    - Assuming you have logs, what were the services that were somehow not matching the web filter and what rule were they hitting?

    Abdulaziz_Alatar
    New Member
    January 28, 2017

    i think you need configure in webfilter * deny in final 

    frax
    fraxAuthor
    New Member
    January 31, 2017

    Hello rwpatterson,

    the order is correct..maybe could be a bug?

    frax
    fraxAuthor
    New Member
    January 31, 2017

    Hello Abdulaziz,

    I've already set the deny to the end...maybe could be a bug?

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.