Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Herschel_Liang
Collaborator

X11 traffic is being dropped, even with "Any, Any, Accept" rule

sk22180 say that [Note: An "any" rule will not allow ports (6000-6003) (ports that match the X11 TCP built in service) at all, by default. This can be changed: see sk41749 - X11 traffic is being dropped, even with "Any, Any, Accept" rule.]

In our enviroment, our X11 traffic destination port is TCP 6011, why is rejected by rulebase? Is there described not so clear?

 

 

0 Kudos
4 Replies
_Val_
Admin
Admin

X11 is a complex service and cannot be matched to Any-Any-Accept, and the SK explains. You need to create a rull with X11 specified in the Service column for it to be properly accepted.

0 Kudos
Herschel_Liang
Collaborator

Look at screenshot, X11 default tcp port should be 6000-6063 but not 6000-6003.

0 Kudos
Maarten_Sjouw
Champion
Champion

X11 is one of the few services that has always been excluded from Any, so you need to add a rule above with X11 in it. Or you need to adjust the X11 service itself and allow it to Match for Any.
Regards, Maarten
0 Kudos
Timothy_Hall
Champion Champion
Champion

Or you can uncheck this somewhat hidden Global Properties checkbox to disable this behavior regarding X11 ports:

x11.png

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events