Hi Guys,
First time posting on Checkmats so my apologies if I've posted in the wrong section.
I've run into a strange issue that I can't wrap my head around and was wondering if anyone else has run into this issue and could potentially help me figure it out. I've also scoured the User Centre for any SK regarding this issue with no luck.
I have a rule in my policy that allows a bunch of VPN Domain subnets to connect to destination X via tcp.3389.RDP (custom Service object). However, the traffic is being denied on the cleanup rule as its being matched under a different Service "Remote_Desktop_protocol" which I believe is a default Service object.
The drop is correct as there is no rule allowing this specific src to dst traffic via the service object "Remote_Desktop_protocol". However, the traffic should be getting matched via the tcp.3389.RDP service object which is in a rule far above the drop rule.
I would like to know how does the Gateway differentiate between the two service objects (other than ID) and why it prefers to match the traffic with the "Remote_Desktop_protocol" service rather than the custom tcp.3389.RDP service. When both service objects are configured exactly the same and the custom tcp.3389.RDP service is referenced above the cleanup rule.
With both Service objects being the same with the same port ranges one would think that due to the custom service being first in the policy base it would be the rule to get matched, not the cleanup rule due to the traffic not being matched and then also being specified as Remote_Desktop_protocol.
Any help figuring this out would be greatly appreciated.
Kind regards.