RUT 956 Firewall rules not working on new devices

I have setup the following firewall rules to only allow https and ICMP to internet and block the remaining in and outbound traffic:

These rules have worked fine for weeks but all of the sudden they stopped working on new devices, devices that already worked remain working but new devices that are enrolled with the same config break.

First it looked like an issue in the new firmware 00.07.16.3, so i downgraded to 00.07.15.4 as this was the version i created the master config with but it remained broken.

Am i doing something wrong here? When i disable the block all outbound rule then i can access our services again.

Hello,

Thank you for reaching out. Your request is currently under review and analysis. Once the evaluation is complete, I will get back to you with an update and further information, findings, or suggestions.

Thank you for your patience.

Best regards,

Goodmorning,

Any update on this? We are now stuck and cannot continue further deployment

Hello,

Apologies for the delay. I was unable to replicate similar firewall behavior on my side (FW 7.17.3). Could you please provide a screenshot from the Firewall Zones page (Network → Firewall → Zones)?

Additionally, if feasible, you could try updating firmware to 7.17.3, if preferred, without Keep Settings selected, reconfiguring traffic rules, and making them appear at the top of the traffic rules page.

Best regards,

No worries,

Hmm interesting, we avoided the latest version because its not marked as stable yet but i will give it a try. Yes see below:

At the top? The rules work based on posistion correct? So if the block is at the top then it would overrule everything below it no?

Hi,

Any update :grinning_face_with_smiling_eyes:

Tested the same settings again on 00.07.17.4 but the connection still times out, turning off the block all outbound rules restores the connection.

I seem to have found a fix, so if i add http to the allow https rule then it works again, but when i remove the http port again it keeps on working just fine. :melting_face:

Hello,

Thank you for your patience.

From the first review, it seems your “allow outbound HTTPS” rule is not defined correctly. On the LAN side, port 443 should not be specified, since an outbound connection does not originate from port 443 in NAT.

Best regards,

You would suggest the following?

But then i am still confused why this config has worked fine for months :sweat_smile:

Yes, if necessary, UDP can be added as well. With this corrected rule, it should allow forwarding HTTPS outbound traffic from LAN. Let me know if it works.

Hi,

Can confirm that only setting 443 at the destination port fixed the issue, but i find it weird that sometimes it works just fine :thinking: I have noted it down and want to thank you for your help!

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.