Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Stefano_Chiesa
Explorer

HTTP ACCESS enbled by implied rule

Hello all.

I noticed that HTTP access to each of nodes in a cluster is enabled by implied rules.

Is there a way to disable it? Maybe locally because the customer have 5 clusters under the same Management and I would like to avoid global changes...

Below the enabled blades and the log row.

Thanks in advance.
Regards.

Stefano.

2020-02-17 11_52_48-mRemoteNG - confCons.xml - S-MI-SVIL.png

2020-02-17 10_35_44-mRemoteNG - confCons.xml - S-MI-SVIL.png

0 Kudos
5 Replies
G_W_Albrecht
Legend Legend
Legend

0 Kudos
_Val_
Admin
Admin

Yes, GWs are allowed to open outgoing connections via implied rules. This is usually required for normal functions. If you change that, some features: AVI & IPS updates, URL and AC categorization and others, may not work.

Why are you concerned with this in the first place?

0 Kudos
Stefano_Chiesa
Explorer

Hi Val_Loukine, thanks for your answer.
A vulnerability scan found the HTTP port open and has it been marked as weakness, the customer asked to close it....
0 Kudos
_Val_
Admin
Admin

So it is not gateway originated connection, the other way around.

Firstly, having http port open does not mean vulnerability. 

GW may have one or more portals: WebUI, Mobile Access, Identity Awareness, etc. Those are also needed for functioning correctly. If you are concerned with WebUI being accessed from outside of protected perimeter, you can change the port and interfaces it is available through on GW object, Portals tab

0 Kudos
Stefano_Chiesa
Explorer

Thanks, I'll check the active (and needed) modules.

Regards.
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events