sk180808 - Security Gateway accepts HTTP/HTTPS traffic by an implied rule for its HTTP/HTTPS Web Portals, although there is an explicit rule to drop this HTTP/HTTPS traffic
Security Gateway accepts HTTP/HTTPS traffic by an implied rule for its HTTP/HTTPS Web Portals, although there is an explicit rule to drop this HTTP/HTTPS traffic
Product: ClusterXL, ElasticXL, Maestro HyperScale Firewall, Scalable Chassis, Security Gateways, VSNext, VSX (Traditional)
Version: R81 (EOS), R81.10 (EOS), R81.20, R82, R82.10
OS: Gaia
Last Modified: 2025-12-23
Symptoms
- The Security Gateway accepts HTTP/HTTPS traffic by an implied rule for its HTTP/HTTPS Web Portals, although there is an explicit rule to drop this HTTP/HTTPS traffic.
Cause
When you enable the Web Portal for more than one Software Blade in the Security Gateway / Cluster object, by design it is possible to configure the accessibility "According to the Firewall policy" for only one Web Portal at a time.
As a result, you must configure the accessibility of other Web Portals as "Through internal interfaces" or "Through all interfaces". The Security Gateway / Cluster accepts the traffic for these Web Portals with the applicable implied rules before the explicit "Drop" rules.
Solution
We're here for you
Please log in / sign in to view solution
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: Advanced
Status: Approved by TAC
Date Created: 2023-04-13
Last Modified: 2025-12-23