Traffic getting hits on non-allowed URLs

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Traffic getting hits on non-allowed URLs

L0 Member

Hi All,

 

I have been experiencing a situation where http and https traffic are getting hits on 1 of my security policies which is configured with Custom URL Category.

 

It looks something like this:

 

Source Zone: Internal

Source: Internal Network

Destination Zone: External

Destination: Any

Application: Any

Service: HTTP & HTTPS

URL Category: *.testing.com & testing.com

 

I have seen several discussions pertaining to similar issues but none of them are really the same. On traffic logs I am seeing application as insufficient-data, incomplete and being resolved to SSL / web-browsing.

 

I am hesitant to disable the rule as this device is serving a large amount of users and I do not wish to disrupt internet connectivity.

2 REPLIES 2

Cyber Elite
Cyber Elite

@KelvynYeo,

Whenever you use categories as match criteria, the first such rule will get hit in the rulebase as the firewall has to allow enough traffic to pass to see what the domain is going to be. Once it can actually identify the domain in question, it'll continue through the rulebase as you'd expect to verify if there's a matching entry.

Hi @BPry ,

 

Would the best approach to this situation be tightening down the rule with FQDN objects rather than URL category?

 

As I have mentioned, there are actually a huge load of traffic that passes through this security rule and I am seeing tcp-fin for session end even for those mismatched URLs.

 

This is concerning as it would mean that sessions are being established with this rule and it is not supposed to be the case. This is a legacy rule that was migrated from CISCO ASA and we are looking to retain it as part of user's requirement.

  • 1221 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!