Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: Port forwarding failing despite following KB4740 and three-step guide

$
0
0

The messages are from the screen service that detects outside of normal volumes in various traffic and then supresses those further connections.  If this is a false positive of legitimate traffic you can go to the screen section and raise the limits or turn off the particular option.

 

Rishi,

 

The topology is cable modem > SSG with port forwarding on both UDP and TCP for the same port.

 

The issue is that the SSG will only allow ONE protocol either TCP or UDP per PORT.  So it is allowing the tcp connection for port forwarding but NOT the UDP one. 

 

We have validated that both TCP and UDP are forwarding from the cable modem.

 

WG91,

What the development team needs is validation of the above, UDP arrives on the port:

collect this with snoop showing the UDP packets arriving

 

The rules are in place that should allow UDP.

This is the get tech file.

 

There are no sessions created for the UDP traffic.

This is the debug with the source/destination showing now sessions.

 

So what is missing for the complete package for JTAC is the snoop capture showing the UDP packets arriving on the interface.

 


Viewing all articles
Browse latest Browse all 2577

Latest Images

Trending Articles



Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>