cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1415
Views
0
Helpful
4
Replies

block access rule does not works

gogi99
Level 1
Level 1

i have the firepower 1120 firewall, i have a network in DMZ zone. i natted my server and when i create block access rule for ping, this rule does not works. also, i noticed that my firewall allow all to my server, all open ports are allowed

4 Replies 4

gogi99
Level 1
Level 1

when i set default access rule on block nothing does not works

Your access-rule doesn't work because you only block traffic from outside to outside.

For a firewall deployment you should use the default deny and allow everything you need. And pay attention on using the correct zones.

if i set default deny, allowing port on natted device  i set access rule from any (outside zone) to local ip address of my server (172.16.20.x insied zone) or on natted ip address?

You habe to use the real IP (that is the one used in the DMZ on the server) in your access-control rule.