Traffic is unexpectedly allowed
A few things to try, either to block problematic traffic, or to narrow down the cause:
- Because traffic to private destinations is blocked by default, this means there is one or more existing rules that explicitly allows this traffic. You will need to find any such rules.
- Make sure the applicable rule is enabled (toggle at top of rule page)
- Make sure IPS is not disabled in the rule default or in the rule. Any rule tagged to use the default setting continues to use the default setting even if the default setting has changed.
- Make sure Decryption is not disabled in Global Settings.
- Check each rule component (rule action and each posture and security control) to be sure each specifies the behavior you expect.
- Check to see that an expected exception to connect to the private resource appears as expected on the Traffic Steering page (Connect > End User Connectivity > Zero Trust.)
- To immediately block access to a problem destination that is unexpectedly being allowed, you can create a new access rule (using the "Enter manually" option for source and/or destination if necessary) and put this rule at or near the top of the rule list on the Policy page so it hits before more general rules that would otherwise apply to the traffic.