Internet traffic is unexpectedly allowed
A few things to try, either to block problematic traffic, or to narrow down the cause:
- Verify that any existing rule blocking the traffic is enabled (toggle at the top of the rule page)
- To immediately block access to a problem destination that is unexpectedly being allowed, you can create a new access rule (using the "Enter manually" option for source and/or destination if necessary).
- Make sure decryption is not disabled in the security profile in the rule that matched the traffic, or in the security profile selected in Rule Defaults.
- Make sure IPS is not disabled in the rule default or in the rule
- Make sure Decryption and Certificate Pinning are not disabled in Global Settings.
- Make sure the destination is not on a Do Not Decrypt list used by the IPS feature or specified in the rule's security profile.
- Make sure web features are being enforced for the rule (Advanced settings at bottom of Security Controls section in the rule)
- Check the configured sources and destinations of the rule you expect to block the traffic to be sure they include the problematic source and destination.
- Check each rule component of the rule you expect to block the traffic (rule action and each security control) to be sure each specifies the behavior you expect.
- Check the rule order; traffic may be hitting a different rule than the one you expect.