security policy order not working.

Showing results for 
Show  only  | Search instead for 
Did you mean: 

security policy order not working.

L3 Networker

I have a policy from trust to untrust any any allowed. I have cloned this policy and put on top of this with  address -test and deny 2 applications. This address is an ip for eg. which is reserved in dhcp. But I can see apps being access via any any policy. Should the address be blocked using block policy.


L6 Presenter



Most likely not all conditions were met in the 1st policy, so traffic passed through the any any.

Did you check detailed logs from any any to see why it didn't match 1st policy ( sorce ip, destination , postrs, )?




Cyber Elite
Cyber Elite

Is this a web applicaion and do you use SSL decyrption? If you are not using SSL decyption and are attempting to block two app-ids it's pretty common for this to not actually work. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!