Hello.
I have an explicit rule for SNMP traffic, through a S2S VPN.
The rule is working fine, except for SNMP traffic, because when our manager (Zabbix) sends SNMP requests (UDP/161) to resources on the other side of the VPN, the traffic is MATCHING with a "free" rule that is below our explicit rule.
Explicit Rule -> #98
Src: Local_Network_CP
Dst: Red_Remote_Cisco
Service: SNMP, SSH, HTTP, HTTPS
Action: Accept
Free Rule -> #140
Src: Red_Local_CP
Dst: Any
Service: Any
Action: Accept
Traffic such as SSH, HTTP, HTTPS, does match our explicit rule, but SNMP does not.
Any idea why this might be happening?
Regards.