Hi CheckMates,
I hope you are able to assist me. I am getting crazy working with inline layers. Therefore I have temporary moved to the classical rules based firewall rules.
Errors I see while using inline layers are shown in the smartevent indexed log.
I have tried to build a fw rule uing inline layers.
id | | Source | Destination | Services & App | Action | Track |
10 | | OOB-NETWORK | OOB-NETWORK | any | OOB-internal | n/a |
10.1 | | any | AAA-Servers | [AAA-Services] | ALLOW | LOG |
10.2 | | any | ay | any | DROP | LOG |
11 | | ANY | OOB-NETWORK | any | OOB-incoming | n/a |
11.1 | | any | AAA-Server | RDP ICMP-REQUEST | ALLOW | LOG |
12 | | OOB-NETWORL | any | any | OOB-Outgoing | n/a |
12.1 | | | | | | |
12.2 | | any | any | any | DROP | LOG |
When I look into SmartEvent logs
Sometimes I get a hit on the rule base lets say 10.1 but other time it says 2.1.
I cannot figure out why it atually tells me it touches rules 10.1 and second line in the layer it drops on 2.1? Where comes the rule 2.1 because it doesn't exist.
I am running VSEC on VM with R81 take 10 and SMS runs R81 Take 10.
Is it a bug when it writes 2.1 or is it me configuring inline layers wrongly?
This one error.
This one is okay.
Hope you CheckMates can give me some hints were to look. Expect to contact TAC next week but maybe you guys have an idea of what is going on.
Best Regards
Kim