Got it

Security policy not working even if configured correctly to block torrents

Latest reply: Dec 20, 2021 14:18:08 1218 10 9 0 1

Problem Description


  Torrents downloading block on the Network not working, so users can download normally.


Problem Analysis


1. We checked the policy corresponding to torrent downloads and found it was not ticked.


095049komn66xt64spx6hz.jpg?1.jpg


2. We checked the Firewall session table and found the policy did not match.

 

095058qc44rahzbdl24bzr.jpg?2.jpg


3. We checked the engine state and found it in bypass mode:


095107p2nnjio1gggf2npn.jpg?3.jpg


Root Cause


The engine is in bypass mode, so it bypasses the traffic.


Solution


We undo the engine bypass.


095348ov09l0080cau90v0.jpg?4.jpg


And then the engine works normally.


095402n7n54w3obw5nnn1c.jpg?5.jpg


The policy is ticked and the users can’t download the torrent. 




Security policy not working even if configured correctly to block torrents-2892961-1
View more
  • x
  • convention:

ohh sweet heart you saved my day ;) I have establish l2tp over ipsec but my untrust to trust policy was not getting hit/working even after configuring in right way and what I found is something new, even my firewall engine was not in bypass mode but it seems if you change policy so many time quickly it stopped working. To solve the issue I retweak your suggestion and forefully made firewall bypass and then renoved bypass and guess what, it is working now :) seems some bug or what you say ?
View more
  • x
  • convention:

@Mohamed_Mostafa hey bro, thanks for your helpful case.Security policy not working even if configured correctly to block torrents-2893663-1
View more
  • x
  • convention:

It seems I ain't that much lucky :p it worked once and again its not working, I think I should upgrade the software.

Current version is as below.

USG6370 V500R001C30SPC100

what you professional suggest ?

Kindest regards,
Uzair
View more
  • x
  • convention:

Dear uzzi ,

Your recommended s/w is :
USG6300 V500R001C60SPC500
https://support.huawei.com/enterprise/en/security/secospace-usg6300-pid-8661805/software/22854326

And latest patch is :
USG6300 V500R001SPH019
https://support.huawei.com/enterprise/en/security/secospace-usg6300-pid-8661805/software/23590747

You can test the recommended software and latest patch
View more
  • x
  • convention:

Posted by chenhui at 2019-03-20 18:43 @Mohamed_Mostafa hey bro, thanks for your helpful case.
You are welcome brother
View more
  • x
  • convention:

Thanks Mostafa, I have downloaded the software however for patch it need approval and I already have submit the request. Lets hope I will hear from them, by the way did you observe any case where policy was not working and after software upgrade issue got solved ? surprisingly last night it worked after bypass module on/off but then never did, its pretty straight forward configuration and ideally it should work :)

Thank you again.

Kindest regards,
Uzair
View more
  • x
  • convention:

I have you can solve your issue soon , you can contact TAC service for support and they will help you .
View more
  • x
  • convention:

Wonderful and useful, you deserve helpful
View more
  • x
  • convention:

12
Back to list

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.