- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-21-2023 12:35 AM
Hi,
We have a security rule set up to allow voip traffic from A to B but limited to certain ports.
We are see an allowed traffic that matches the source and destination but however has a port number that is not in the list of allowed ports, with end reason aged out.
I would like to know how does the firewall actually do a lookup on the security policy as technically if the port number does not match traffic shouldn't be allowed.
12-21-2023 04:56 AM
are your ports set as services or as application-default?
if you're seeing ports you didn't expect, the session is most likely being allowed by a different rule
are you able to provide screenshots?
12-21-2023 06:09 AM
I'm unable to provide screenshots.
ports are set under services. i can see traffic logs hitting the voip rule.
weird thing is that port that is being allowed is not in the list of allowed ports.
12-22-2023 06:35 AM
When you say you allow "voip" traffic, what's the actual application? Is that application the only defined application on the rule? When you say "A to B" you have a defined source and destination IP objects/networks? As for the service (ports that are allowed and also not matching), are you certain the service object you're using isn't a service range?
To confirm you're saying the rule looks like this?
Source --> 1.1.1.0/24 (internal zone) | Destination --> 2.2.2.0/24 (internet zone) | Application <defined application> (not app any) | Service --> <specific ports defined> (Service 'Any' not selected in the drop down, as well as tcp/udp is defined on the service)
You're saying you have these options configured and you're seeing a port being allowed on this rule from a session allow / end?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!