My guess would be they wanted a logging profile on the default rules and did not know how to override them...
@reaper wrote:well their untrust untrust allow does not do anything in it's own as the default policy would already do what it does (allow intrazone traffic)
you could certainly rebuild that policy to only allow the applications you want, like ike and ipsec, and then set the default rule to drop instead of allow, or create a deny all rule for untrust at the end
The default rules don't do anything in this case because there is an explicit deny any rule above them. The untrust -> untrust rule is above the deny all rule
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!