Strange firewall policie
edited October 2019 in Firebox - Other
I have discovered a strange firewall rule that looks like this and it is in top (no #1)
1. Any From Firebox Any Firebox Any Any
I cannot edit it nor delete it, it just says "ou cannot modify this default object."
The rule was added back in -2012 (the config is probably that old or older and fw has been upgraded to new model(s) over the years).
How can I get rid of that policie (?), using CLI perhaps?
Tried both GUI and WSM.
Sign In to comment.
I tried to do it in CLI:
WG(config/policy)#no rule "Any From Firebox"
Error: "You cannot modify this default object."
But no luck :-(
I also tried to open the config file offline and remove the rule, then I got this message:
"Policy: Any From Firebox cannot be deleted because it is either a predefined, DVCP-created, template-created, or Dimension managed VPN policy"
unselect Global Settings -> General -> Enable configuration of policies for traffic generated by the Firebox
Thanks, that was it!
Note that unchecking "Enable configuration of policies for traffic generated by the Firebox" won't delete the policy; it just won't show it to you, but it's still there working in the background.
The Firebox NEEDS that policy to operate. It allows the Firebox itself to go out to anywhere it needs for its services.