Skip to main content
ift38375
New Member
December 5, 2014
Question

Services under Firewall Policy not working

  • December 5, 2014
  • 4 replies
  • 6156 views

Hello Experts,

I created policy for LAN to WAN rule with open port 80,443. One of our user was accesing website "https://in.pinterest.com/" but it is unable to connect . WHY ?

 

But when i am select "ALL" in services then it is opening. I want to know that which particular port or service need to add in "Service" option. so that user can access this website.

 

 

KS

    4 replies

    emnoc
    New Member
    December 5, 2014

    1>What service did you define in the  fwpolicy?

     

    2>Did you execute and diag debug flow to see if it was matching that fwpolicy ( by policy-id)

     

    3>and to go along with #2, did you validate the fwpolicy sequence and ordering ?

    ift38375
    ift38375Author
    New Member
    December 5, 2014

    emnoc wrote:

    1>What service did you define in the  fwpolicy?

     

    2>Did you execute and diag debug flow to see if it was matching that fwpolicy ( by policy-id)

     

    3>and to go along with #2, did you validate the fwpolicy sequence and ordering ?

    Hello Emnoc,

     

    1. http =80 and https=443

    2. this command is not showing any logs, how to perform this task

    3. how can we validate Sequence and ordering

    emnoc
    New Member
    December 5, 2014

    ift38375 wrote:

     

    2: this command is not showing any logs, how to perform this task 3. how can we validate Sequence and ordering

     

    For #2, search for diag debug flow you have many filter options apply a filter to match the traffic port src or dst and review the diagnostic output. If it matches the firewall policy  than inspect the firewall policy, if it doesn't match the specific firewall policy than determine why ( routing, some other external issues )

     

     

    For #3; I prefer the cli but the webgui  shows the same thing with regards to the ordering of policies

     

    If the policy sequence is nor correct , move it around to ensure the most specific are place before a broader fwpolices.

     

    lastly, double check for any NAT issues if  the client src is an rfc1918 addressed.

     

     

     

    Dave_Hall
    New Member
    December 5, 2014

    @ift38375

     

    Also does this problem happen from all web browsers? 

    And have you tried to access the website from another computer?

    Any UTM features enabled on that firewall policy?

     

    Nslookup (using www.kloth.net) reports in.pinterest.com resolves to:

     Non-authoritative answer:
     in.pinterest.com canonical name = www.pinterest.com.
     www.pinterest.com canonical name = www.pinterest.com.edgekey.net.
     www.pinterest.com.edgekey.net canonical name = e9343.a.akamaiedge.net.
     Name: e9343.a.akamaiedge.net
     Address: 172.227.88.170

     

    You have anything in place that is blocking any of those addresses?

     

     

     

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!