Hello ya'lll.
I'm having an issue, and I have no doubt I'm missing something simple, but try as I might I can't figure it out.
I'm setting up some Policies for "bypass" to allow servers to get out to the Internet for updates for certain products, and for our RMM tool.
Thing is, I've added bypasses for HTTP (80) and HTTPS (443) for several domains (*.packages.chocolatey.org and *.activeupdate.trendmicro.com) and they STILL show up in the "DENY" log. I can't figure out why it keeps getting "blocked".
I'm sure I'm missing something simple. Any guidance it massively appreciated.
-jb
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Run a debug flow and see what it says. https://docs.fortinet.com...ugging-the-packet-flow
Thanks for the reply.
I followed the instructions, using the IP of the site that the Fortinet Logs are showing hitting the "deny" policy, and the debug screen shows...nothing.
Undoubtedly I'm doing something wrong, because the FW is showing the traffic as being dropped in the Logs, but the debug screen shows Jack and Shiza....
Thanks again for the help. This profiel is multi-vdom and is Profile Mode, if that makes a dfference.
I'd start by looking attentively at the drop log - it says the reason for a drop, what is it?
ActionDeny: policy violationThreat131072PolicyBlock (1)Policy UUIDfaf9f460-16b8-51ea-7f86-f61019f89d9dPolicy TypeIPv4
nothing helpful. "Policy violation"
Again, the frustrating thing is that both the SRC and DST ips/FQND's have a policy to ALLOW the very traffic that's being blocked
. I don't understand how they're slipping through the respective "allow" policies.
-jb
Is your firewall in NGFW Mode with Central NAT?
No to Central SNAT. It is Multi-VDOM Profile Based (not policy based).
Quick question.
How are you matching a site such as *.packages.chocolatey.org ?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1645 | |
1070 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.