- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: Remote Access VPN/App+URL Policy Enforcement w...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Remote Access VPN/App+URL Policy Enforcement when split tunneling is disabled
R80.10 Manager
R80.10 VSX with handful of virtual systems
1 Virtual System is handling Endpoint Security VPN:
- Allow to route through gateway is set
- Route through gateway is forced via global properties settings
- ipchicken confirm public ip is that of gateway
- Rule that reads:
- src: vpn_pool
- dst: Internet
- URL Category attempting to block
- Action Block/UserCheck Message
Issue: App/URL Policy is not applied to these users even though they are routing through gateway, is this expected behavior?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Turns out it was rule order. There was a rule that was set to inspect for content with source of any and it was getting hit first even though remote access rule and subsequent rule to block certain content were after this rule was catching on first rule.
--Juan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What rule is actually accepting the traffic?
What's being logged?
Perhaps that might provide a clue.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Turns out it was rule order. There was a rule that was set to inspect for content with source of any and it was getting hit first even though remote access rule and subsequent rule to block certain content were after this rule was catching on first rule.
--Juan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Good to know, thanks for updating.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey Juan,
Can you please explain a little more on how to solve this issue?
