Troubleshooting: no traffic on the access rule after one day up-time.
10/14/2021 7 People found this article helpful 488,337 Views
Description
SonicOS 7.X firmware
The following rule is working normally for about one day, but suddenly drops all the traffic.
- Rule 7 LAN to VPN Allow Service CreditCardPort -> CreditCardPort (Enabled)
- IP: LAN Subnets -> Any Iface: Any (ffffffff) -> Any (ffffffff)
- Policy Name: Custom Access Rule
- UUID: 00000000-0000-0001-0700-2cb8ed694934
- Instance: 1
- ID: 134
- Priority: 7
- Logging: Enabled
- Management: Disabled
- Allow Fragmented Packets: Enabled
- Packet Monitor: Disabled
- Flow Reporting: Disabled
Auto Rule: Disabled - Users: Included: All
- Excluded: None
- Schedule: Always on (on)
- Comment:
- Timeout: TCP:15 minutes, UDP:30 seconds
- IP Version: IPv4
- Properties: 0x0, Priority Type: Auto
- Max Connections: 100% of maximum connections
- Connections: 1
- Src IP connection limit: 128 (off)
- Dst IP connection limit: 128 (off)
- Geo IP Block: 0
- Per Policy Geo IP Block: 0
- Per Policy Geo IP Bitmap: 0
- Per Policy Block Unknown: 0
- Botnet Block: 0
- Enable SIP Transformation: Disabled
- Enable H.323 Transformation: Disabled
- Bypass DPI: No
- Bypass DPI-SSL Client: No
- Bypass DPI-SSL Server: No
- Qos Marking DSCP Action: Preserve
- Qos Marking 802.1p Action: None
- Egress BWM: Disabled
- Ingress BWM: Disabled
- Tracking Bandwidth Usage: Disabled
- Bytes, Packets: Rx: 0, 0 Tx: 0, 0
- Usage : 0
SonicOS 6.5 firmware
The following rule is working normally for about one day, but suddenly drops all the traffic.
- From LAN To VPN
- Current Size : 5
- Maximum Size : 285
- Rule 1 Allow Service CreditCardPort -> CreditCardPort (Enabled)
- IP: LAN Subnets -> Any Iface: Any -> Any
- Logging: Enabled
- Management: Disabled
- Allow Fragmented Packets Enabled
- Packet Monitor: Disabled
- Users: Included: All,
- Excluded: None
- Schedule: Always on (on)
- Comment:
- Timeout: TCP:15 minutes
- UDP:30 seconds
- Max Connections: 100% of maximum connections
- Connections: 1
- Src IP connection limit: 128 (off)
- Dst IP connection limit: 128 (off)
- IP Version: IPv4
- Qos Marking DSCP Action: Preserve
- Qos Marking 802.1p Action: Preserve
- Bytes, Packets: Rx: 0, 0 Tx: 0, 0
- Usage : 0
- Egress BWM: Enabled
- Bandwidth Obj: CreditCardBWM
- Guaranteed Bandwidth: 768 kbps
- Maximum Bandwidth: 768 kbps
- Violation Action: Delay
- Traffic Priority: 0
- Enable Per-IP BWM: No
- Ingress BWM: Enabled
- Bandwidth Obj: CreditCardBWM
- Guaranteed Bandwidth: 768 kbps
- Maximum Bandwidth: 768 kbps
- Violation Action: Delay
- Traffic Priority: 0
- Enable Per-IP BWM: No
- Tracking Bandwidth Usage: Enabled
Cause
Resolution for SonicOS 7.X
This release includes significant user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.
Some apps are using more typical TCP protocol with randomized source ports. In this case, the rule would be too specific on the source port config.
- Rule 1 Allow Service CreditCardPort -> CreditCardPort (Enabled)
Resolution for SonicOS 6.5
This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.
Some apps are using more typical TCP protocol with randomized source ports. In this case, the rule would be too specific on the source port config.
- From LAN To VPN
- Current Size : 5
- Maximum Size : 285
- Rule 1 Allow Service CreditCardPort -> CreditCardPort (Enabled)
Resolution
Resolution for SonicOS 7.X
This release includes significant user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.
Modify the access rule as following.
- Rule 7 LAN -> VPN Allow Service Any -> CreditCardPort (Enabled)
- IP: LAN Subnets -> Any Iface: Any (ffffffff) -> Any (ffffffff)
- Policy Name: Custom Access Rule
- UUID: 00000000-0000-0001-0700-2cb8ed694934
- Instance: 1
- ID: 134
- Priority: 7
- Logging: Enabled
- Management: Disabled
- Allow Fragmented Packets: Enabled
- Packet Monitor: Disabled
- Flow Reporting: Disabled
- Auto Rule: Disabled
- Users: Included: All, Excluded: None
- Schedule: Always on (on)
- Comment:
- Timeout: TCP:15 minutes, UDP:30 seconds
- IP Version: IPv4
- Properties: 0x0, Priority Type: Auto
- Max Connections: 100% of maximum connections
- Connections: 1
- Src IP connection limit: 128 (off)
- Dst IP connection limit: 128 (off)
- Geo IP Block: 0
- Per Policy Geo IP Block: 0
- Per Policy Geo IP Bitmap: 0
- Per Policy Block Unknown: 0
- Botnet Block: 0
- Enable SIP Transformation: Disabled
- Enable H.323 Transformation: Disabled
- Bypass DPI: No
- Bypass DPI-SSL Client: No
- Bypass DPI-SSL Server: No
- Qos Marking DSCP Action: Preserve
- Qos Marking 802.1p Action: None
- Egress BWM: Disabled
- Ingress BWM: Disabled
- Tracking Bandwidth Usage: Disabled
- Bytes, Packets: Rx: 0, 0 Tx: 0, 0
- Usage : 0
NOTE: To modify the rule, plase navigate to Policy|Rules and Policies| Access Rules.
Resolution for SonicOS 6.5
This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.
Modify the access rule as following:
- From LAN To VPN
- Current Size : 5
- Maximum Size : 285
- Rule 1 Allow Service Any -> CreditCardPort (Enabled)
- IP: LAN Subnets -> Any Iface: Any -> Any
- Logging: Enabled
- Management: Disabled
- Allow Fragmented Packets Enabled
- Packet Monitor: Disabled
- Users: Included: All, Excluded: None
- Schedule: Always on (on)
- Comment:
- Timeout: TCP:15 minutes, UDP:30 seconds
- Max Connections: 100% of maximum connections
- Connections: 1
- Src IP connection limit: 128 (off)
- Dst IP connection limit: 128 (off)
- IP Version: IPv4
- Qos Marking DSCP Action: Preserve
- Qos Marking 802.1p Action: Preserve
- Bytes, Packets: Rx: 0, 0 Tx: 0, 0
- Usage : 0
- Egress BWM: Enabled
- Bandwidth Obj: CreditCardBWM
- Guaranteed Bandwidth: 768 kbps
- Maximum Bandwidth: 768 kbps
- Violation Action: Delay
- Traffic Priority: 0
- Enable Per-IP BWM: No
- Ingress BWM: Enabled
- Bandwidth Obj: CreditCardBWM
- Guaranteed Bandwidth: 768 kbps
- Maximum Bandwidth: 768 kbps
- Violation Action: Delay
- Traffic Priority: 0
- Enable Per-IP BWM: No
- Tracking Bandwidth Usage: Enabled
NOTE: To modify the rule, please navigate to Manage | Policies | Rules | Access Rules and select the relevant rule.
Related Articles
Categories
Was This Article Helpful?
YESNO