?
Solved

x700 core blocking sites it shouldn't be

Posted on 2009-07-09
4
Medium Priority
?
527 Views
Last Modified: 2013-11-16
I have a watchguard x700 that is constantly blocking sites (IPs) that should be allowed through due to a policy.  We use OWA and we have a policy setup to allow any HTTPS traffic through to certain IP addresses...one of them being the Exchange server.  Lately the x700 has just been block happy and blocking just about everything.  Once I reboot the x700 it clears our the blocked sites list and users are able to connect for a short time. Then few hours later, sometimes days, their IP will be added to the blocked sites list again and they cannot connect.  Anyone run into this before and if so can you help...its extremely annoying.
0
Comment
Question by:Fveng
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 32

Accepted Solution

by:
dpk_wal earned 2000 total points
ID: 24820204
You must have enabled Auto-block features in policy or at the global level.

In Policy Manager, go to Setup->Default Threat Protection->Default Packet Handling; under unhandled packets, ensure Auto-block source of packets not handled is not checked.

Also, edit the HTTP policy, go to Properties tab; ensure that Auto block sites that attempt to connect is not checked.

Thank you.
0
 

Author Comment

by:Fveng
ID: 24822815
Thanks for the tip.  Auto-block source was checked.  I unchecked it and I'll monitor the blocked sites list to see if that took care of the problem.  Auto block under HTTP or HTTPS wasn't checked so I'm thinking we should be good.
Thanks for your help, I'll accept as solution after testing.
0
 
LVL 32

Expert Comment

by:dpk_wal
ID: 24825412
Sure, please update once tested! :)

Thank you.
0
 

Author Comment

by:Fveng
ID: 24879314
That seemed to resolve the issue.  I haven't had any complaints yet and the blocked sites list is a lot smaller than it was before.
Thanks!
0

Featured Post

WatchGuard's M Series Appliances - Miecom Approved

WatchGuard's newest M series appliances were put to the test by Miercom.  We had great results and outperformed all of our competitors in both stateless and stateful traffic throghput scenarios! Ready to see how your UTM appliance stacked up? Download the Miercom Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

To setup a SonicWALL for policy based routing to be used with the Websense Content Gateway there are several steps that need to be completed. Below is a rough guide for accomplishing this. One thing of note is this guide is intended to assist in the…
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Do you want to know how to make a graph with Microsoft Access? First, create a query with the data for the chart. Then make a blank form and add a chart control. This video also shows how to change what data is displayed on the graph as well as form…
Suggested Courses

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question