- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I have a strange issue where the firewall does not match traffic to spefic rule and ultimately drops the traffic on the cleanup rule.
firewall cluster in HA using VRRP
The rule i expect it to match on is rule 67 whereas cleanup is rule 112 in this policy
The rule looks similar to;
Object_group_src -> Object_group_Dst on TCP/3389 permit and place into vpn community
within the object_group_src there are approx 14 different subnets. all subnets within this group have no issues except for the subnet 10.10.25.0/24, which for some reason bypasses the rule and goes straight to cleanup.
I have checked and quadruple checked the src, dst and service and all should match the rule as intended but the logs still show dropped against the cleanup rule.
I have done a packet capture and confirmed the traffic matches the rule, i have installed policy and database.
I have attempted to create a specific rule to match the traffic to no avail it still goes straight to cleanup.
now i am at a loss
The only things i can see that i can try now is failover the cluster to see if this is just a problem isolated to the single member and or disable secureXL to see if this is misbehaving with the traffic in someway.
any advice would be appreciated.
Using R80.10 if that matters.
It almost seems like your peer does not include the 192.168.34.0/24 in its encryption domain.
That is exactly it Vladimir. Putting the VPN community in the VPN column will not force traffic into the tunnel as interesting, only the VPN domains can do that. @Northy please provide the VPN domain configuration for your firewall and the object representing your VPN peer. If these are not correct it doesn't matter what your rulebase says which is why the rule is being skipped.
There any NATing going on for this tunnel?
I bet that this is a VPN issue.
Both Source (10.10.25.0/24) and Destination are in correct VPN encryption domains? Does VPN in the rule match correct VPN community ?
It almost seems like your peer does not include the 192.168.34.0/24 in its encryption domain.
That is exactly it Vladimir. Putting the VPN community in the VPN column will not force traffic into the tunnel as interesting, only the VPN domains can do that. @Northy please provide the VPN domain configuration for your firewall and the object representing your VPN peer. If these are not correct it doesn't matter what your rulebase says which is why the rule is being skipped.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 15 | |
| 13 | |
| 10 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY