Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted (edited)

I've got a TMG 2010 box here that acts as our firewall. Basically all web access goes through a smoothwall box and out to the LEA and the TMG box is the default gateway for the other access (local LEA and similar)

 

We mainly use this to allow access to specific sites on the LEA's subnets (websites that are effectively internal but not on our network)

 

The primary rule to do this is to Allow access for the internal network to the specified subnets (the LEAs) for HTTP/S and PING etc. This works fine and as expected.

 

However when I run the Traffic Simulator and test whether it would allow access to http://www.madeupsite.com or any actual website it says the above rule matches the packet and allows it!

 

Am I missing something here? With this one rule the destinations are explicitly set to the LEAs server addresses, yet any website 'passes' on this rule! This is the only rule in place as the next rule is the default 'Deny All', the logging actually shows my Allow rule is allowing the access based on a packet match:

 

"The rule Allow local Bypass matches the packet. The packet is allowed."

 

So TMG is saying it would allow access based on the fact it matches on HTTP, even though the destination does not match? I thought the rule had to match everything to be allowed?

 

EDIT: After staring at this for hours I've realised it was all down to a typo!!! :embarassed:

Edited by GoldenWonder

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...