sk180808 - Security Gateway accepts HTTP/HTTPS traffic by an implied rule for its HTTP/HTTPS Web Portals, although there is an explicit rule to drop this HTTP/HTTPS traffic

Security Gateway accepts HTTP/HTTPS traffic by an implied rule for its HTTP/HTTPS Web Portals, although there is an explicit rule to drop this HTTP/HTTPS traffic

Product: ClusterXL, ElasticXL, Maestro HyperScale Firewall, Scalable Chassis, Security Gateways, VSNext, VSX (Traditional)

Version: R81 (EOS), R81.10 (EOS), R81.20, R82, R82.10

OS: Gaia

Last Modified: 2025-12-23

Symptoms

Cause

When you enable the Web Portal for more than one Software Blade in the Security Gateway / Cluster object, by design it is possible to configure the accessibility "According to the Firewall policy" for only one Web Portal at a time.

As a result, you must configure the accessibility of other Web Portals as "Through internal interfaces" or "Through all interfaces". The Security Gateway / Cluster accepts the traffic for these Web Portals with the applicable implied rules before the explicit "Drop" rules.

Solution

We're here for you

Please log in / sign in to view solution

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: Advanced
Status: Approved by TAC
Date Created: 2023-04-13
Last Modified: 2025-12-23