- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Application control & URL Filtering 77.30
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Application control & URL Filtering 77.30
Hi Guys ,
I have r77.30 and not sure why incoming traffic from internet are going through this blade .
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
First of all, how do you know this is happening?
Second of all, do you have any App Control rules where the destination is not "Internet" but, say, "Any"?
Those are my initial guesses.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That answers the first question, how about the second?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Internet is determined by topology.
Which means the egress interface for the traffic from the gateway would be out an "external" interface for this to match.
Can you confirm this is the case?
(Of course, if you're also doing IPS on this gateway, you're taking the Medium Path hit already for the traffic going to your server anyway...)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Mate ,
Thanks for your time . I checked my topology and interface is leading out to Internet . I have internet facing firewall and then that firewall send traffic to the second firewall which is connected to reverse proxy and web server .
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So the traffic is flowing like this:
Internet > FW > (Out external interface) > Other FW > Reverse Proxy > Web Server
If that's the case, it's expected behavior, as I said.
With R80.10 it would be possible to exclude this traffic from App Control with an appropriately designed policy.
