Skip to main content
jason1
New Member
May 21, 2021
Question

Firewall just WON'T LET THIS TRAFFIC OUT!

  • May 21, 2021
  • 13 replies
  • 15630 views

Hello ya'lll.

I'm having an issue, and I have no doubt I'm missing something simple, but try as I might I can't figure it out.

 

I'm setting up some Policies for "bypass" to allow servers to get out to the Internet for updates for certain products, and for our RMM tool.

 

Thing is, I've added bypasses for HTTP (80) and HTTPS (443) for several domains (*.packages.chocolatey.org and *.activeupdate.trendmicro.com) and they STILL show up in the "DENY" log. I can't figure out why it keeps getting "blocked".

 

I'm sure I'm missing something simple. Any guidance it massively appreciated.

-jb

    13 replies

    40james_FTNT
    Staff
    Staff
    May 23, 2021

    Run a debug flow and see what it says. https://docs.fortinet.com...ugging-the-packet-flow

    jason1
    jason1Author
    New Member
    May 24, 2021

    Thanks for the reply.

    I followed the instructions, using the IP of the site that the Fortinet Logs are showing hitting the "deny" policy, and the debug screen shows...nothing.

    Undoubtedly I'm doing something wrong, because the FW is showing the traffic as being dropped in the Logs, but the debug screen shows Jack and Shiza....

    Thanks again for the help. This profiel is multi-vdom and is Profile Mode, if that makes a dfference.

    Yurisk
    SuperUser
    SuperUser
    May 24, 2021

    I'd start by looking attentively at the drop log - it says the reason for a drop, what is it?

     

    yurisk.info - all things Fortinet blog, no ads
    trixsta
    New Member
    May 23, 2021

    Is your firewall in  NGFW Mode with Central NAT?

    jason1
    jason1Author
    New Member
    May 24, 2021

    No to Central SNAT. It is Multi-VDOM Profile Based (not policy based).

    PTM
    New Member
    May 26, 2021

    Quick question.

    How are you matching a site such as *.packages.chocolatey.org ?

    jason1
    jason1Author
    New Member
    May 26, 2021

    Thanks for the reply! I'm using FQDN and wildcard specification for this.

    Specific to "chocolately.org", the FG is saying "unresolved FQDN". However, we have this same problem on many, many other domains, that do resolve the wildcard addresses.

    Example attached:

     

    sw2090
    SuperUser
    SuperUser
    May 27, 2021

    just some hint:

     

    if you use urlfilter rules check the order and mode of your rules. Deny rules have to be the last and allowing rules have to come before it as rules are processed top down. Also if there is a deny rule in urlfilter you have to set allowing rules to "exempt" instead of "allow" to have the urrlfilter stop processing rules once it hit the first one that matched.

    Otherwise traffic would be denied even if there is an allowing rule before the deny one.

     

    Policies are processed the same way. So make sure you bypass policies come in front of the deny policy(s). Otherwise the deny policy(s) would match first and policies - so to say - are allways "exempt".

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!