- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Re: SMB Access Policy Control and internet access
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SMB Access Policy Control and internet access
I'm stuck why this doesn't work, but basically I'm trying to allow devices connected to the LAN network of my SMB device access to the internet over certain ports.
Background: Locally managed 1430 appliance running R77.20.87
Access Policy (Firewall) is set to strict.
I've created a manual rule in the policy to allow internet access (top rule under Outgoing access to the Internet):
The service group "CFU_Internet" contains http, https, and ICMP.
What I'm seeing is traffic from the LAN network (172.x.x.x) to the internet is getting dropped on the last rule in the policy (rule 5 under Incoming, Internal, and VPN traffic):
What am I missing? Why isn't this traffic allowed by the first manual rule I created?
Dave
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Inspiration struck in the middle of the night. The reason this is not working is that I do not have an internet connection defined/configured. Traffic from the LAN networks bound for the internet goes out the DMZ interface which is connected to an MPLS network, which eventually comes back to our datacenter and out our internet egress point there. I had to get a bit creative with the routing (solution found in another CheckMates post) but everything is working now as I need it.
Thanks for everyone's suggestions,
Dave
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is your internet connection connected to a "WAN" port and what build of R77.20.87 firmware is used?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Does 1st rule even have any hits? I noticed in the dropped log, shows inzone Internal and outzone as DMZ.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Using "Strict" is not really recommended out of my experience - i would suggest "Standard" with TP is secure enough 😉 You have to allow every detail in many seperate rules in strict mode, and that needs much knowledge...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Inspiration struck in the middle of the night. The reason this is not working is that I do not have an internet connection defined/configured. Traffic from the LAN networks bound for the internet goes out the DMZ interface which is connected to an MPLS network, which eventually comes back to our datacenter and out our internet egress point there. I had to get a bit creative with the routing (solution found in another CheckMates post) but everything is working now as I need it.
Thanks for everyone's suggestions,
Dave
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Excellent work @David_C1 👍
