Why is this traffic allowed when the rule should not allow it?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Why is this traffic allowed when the rule should not allow it?

L4 Transporter

 

I am tidying up some rules that were "rush" jobs as part of the initial deployment.

 

One rule "TEST-VI" was 

SRC ZONE - TRUST  
DST ZONE - Partners
DST Addr - I%%%%%A-VIP

Application - Any

 

I was going to get rid of this as there is another rule after it with "Service 20,988,5678" which would be a better match.

 

But when I looked at the tracffic for the rule "TEST-VI"

 

???I see traffic going in both directions "Trust -> Partners" but also "Partners -> Trust"???

 

The NAT rule matches the sources and destinations.

Source (Trust) = 128.%.%.22
Dest (Trust) = 128.%.%.244
Source Translated = 192.%.%.111
Dest Translated = 192.%.%.254

 

Why is the security rule allowing the traffic Partner to Trust??

Is it just the perculiarity of the firewall knowing "FTP" creates new return sessions and these are allowed logged? I can't see anything in the opposite direction for the other services.

 

Thanks

 

Rob

 

palo.jpg

 

 

2 REPLIES 2

L5 Sessionator

Hi @RobinClayton

 

You're correct with your comment "Is it just the perculiarity of the firewall knowing "FTP" creates new return sessions and these are allowed logged? I can't see anything in the opposite direction for the other services."

 

It is the way that the firewall is creating "predict" sessions for FTP ALG.

 

https://live.paloaltonetworks.com/t5/Learning-Articles/Palo-Alto-Networks-Firewall-Session-Overview/...

 

https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/app-id/application-level-gateways

 

As a "workaround" to this, you can create an Application-Override policy for the FTP traffic which would in turn disable FTP ALG.

 

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Create-an-Application-Override-fo...

 

Thanks,

Luke.

Ahh good, that means I should be good to disable the bad rule and leave the correct rule and ALG to do the job.

 

Thanks

 

Rob

  • 2596 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!