Quantcast
Channel: SRX Services Gateway topics
Viewing all articles
Browse latest Browse all 3959

Using fully qualified domain names in security policies - traffic will be drop

$
0
0

Hello,

 

i have a SRX1500 with Junos 15.1X49-D75.5. I created a security policy like this:

 

policy pol_DMZ-MDM_to_Untrust-ISP1_Apple_feedback {
match {
source-address H_Airwatch-MDM_10.39.198.2;
destination-address H_feedback.push.apple.com;
application S_TCP_2196;
}
then {
permit;
}
}

 

The connection doesn't work.When i set the destination adress to "any", the connection works fine. The SRX resolves the fqdn periodically:

 


Policy: pol_DMZ-MDM_to_Untrust-ISP1_Apple_feedback, action-type: permit, State: enabled, Index: 24, Scope Policy: 0
Policy Type: Configured
Sequence number: 1
From zone: DMZ-MDM, To zone: Untrust-ISP1
Source addresses:
H_Airwatch-MDM_10.39.198.2: 10.39.198.2/32
Destination addresses:
H_feedback.push.apple.com: 17.188.161.75/32
H_feedback.push.apple.com: 17.188.164.13/32
H_feedback.push.apple.com: 17.188.166.143/32
H_feedback.push.apple.com: 17.188.162.137/32
H_feedback.push.apple.com: 17.188.167.200/32
H_feedback.push.apple.com: 17.188.160.76/32
H_feedback.push.apple.com: 17.188.168.12/32
H_feedback.push.apple.com: 17.188.166.90/32
Application: S_TCP_2196
IP protocol: tcp, ALG: 0, Inactivity timeout: 1800
Source port range: [0-0]
Destination port range: [2196-2196]
Per policy TCP Options: SYN check: No, SEQ check: No, Window scale: No

{primary:node0}
admin@FW> show security policies policy-name pol_DMZ-MDM_to_Untrust-ISP1_Apple_feedback detail
node0:
--------------------------------------------------------------------------
Policy: pol_DMZ-MDM_to_Untrust-ISP1_Apple_feedback, action-type: permit, State: enabled, Index: 24, Scope Policy: 0
Policy Type: Configured
Sequence number: 1
From zone: DMZ-MDM, To zone: Untrust-ISP1
Source addresses:
H_Airwatch-MDM_10.39.198.2: 10.39.198.2/32
Destination addresses:
H_feedback.push.apple.com: 17.188.129.159/32
H_feedback.push.apple.com: 17.188.131.27/32
H_feedback.push.apple.com: 17.188.141.26/32
H_feedback.push.apple.com: 17.188.139.156/32
H_feedback.push.apple.com: 17.188.129.153/32
H_feedback.push.apple.com: 17.188.128.157/32
H_feedback.push.apple.com: 17.188.137.28/32
H_feedback.push.apple.com: 17.188.128.154/32
Application: S_TCP_2196
IP protocol: tcp, ALG: 0, Inactivity timeout: 1800
Source port range: [0-0]
Destination port range: [2196-2196]
Per policy TCP Options: SYN check: No, SEQ check: No, Window scale: No

 

Does anybody know what's the problem is? 

 

bye,

steffi

 


Viewing all articles
Browse latest Browse all 3959

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>