Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
corbypower
Explorer
Jump to solution

Cleanup rule is not dropping traffic

We have a Quantum Spark 1535, R81.10.17

It is set up with "Access control: strict"

There's an outgoing cleanup rule set to drop all traffic from "any" to "internet"

And yet it's been allowing outgoing https traffic from desktop clients, and from other arbitrary ports I try

I've added a manual rule at the bottom of the list to drop  HTTP/S traffic from "internal LAN" to "internet" ( and will add another to drop everything else as I test it.)

This works to block web traffic except via our proxy - which tells me that this traffic is not being accepted in error by a preceding rule, and is also not being caught by the cleanup rule.

I don't understand why the default cleanup rule is not kicking in.

Thanks for any pointers!

 

 

Application & URL filtering is off (there's an internal web proxy)

Several outgoing rules are set to allow web traffic from the web proxy,  DNS requests from the domain controllers, which work and are logged

 

 

 

0 Kudos
2 Solutions

Accepted Solutions
_Val_
Admin
Admin

The cleanup rule should be Any-Any-Drop, not Any-Internet-Drop, IMO

View solution in original post

0 Kudos
the_rock
MVP Diamond
MVP Diamond

Val is 100% right. Here is why it does NOT work in your case. To use object "Internet", you need to have urlf blade on. If its off, that rule would never work.

Just do any any block, it will function, for sure. Or, enable urlf and then existing one will work as well.

Best,
Andy
"Have a great day and if its not, change it"

View solution in original post

0 Kudos
5 Replies
_Val_
Admin
Admin

The cleanup rule should be Any-Any-Drop, not Any-Internet-Drop, IMO

0 Kudos
Tom_Hinoue
Advisor
Advisor

I believe we had a case with TAC regarding strict mode on LMM Spark about some connections are somewhat passed and not blocked as expected, which is maybe caused by strange implicit rules. You may want to open a case with TAC to get a latest R81.10.17 build to see if your issue resolves.

0 Kudos
the_rock
MVP Diamond
MVP Diamond

Val is 100% right. Here is why it does NOT work in your case. To use object "Internet", you need to have urlf blade on. If its off, that rule would never work.

Just do any any block, it will function, for sure. Or, enable urlf and then existing one will work as well.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
corbypower
Explorer

OK, thank you. The rule in question is of course automatically generated, so I can't change it.

I'll just go with a manual rule. 

I was worried something's wrong, but it looks like a quirk I can live with.

Thanks for the help!

(1)
the_rock
MVP Diamond
MVP Diamond

No worries, we are always glad to help.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events