Summary of firewall port blocking failure
background
PetroChina xx9:00:36
Two Sanying refueling machines at a certain station were scanned by the headquarters and opened TCP 20000 port, which needs to be closed. However, after adding policies to the router on the remote station, it still doesn't work. The test still works. Please take a look. The tanker IP 10.91.107.71/72, you can remotely station on the oil server, and then log in to the gateway router through IE to see
PetroChina xx 9:01:12
I added a deny entry to the router firewall forwarding rule in the untrust to trust zone.
solve
1 After a review, it was found that the configuration was not wrong at all
Please invite my classmate network Daniu Xiaoyue to help, after analysis, there is no answer.
3 Call Huawei customer service, customer service doubts whether the traffic arriving at the host passes through the firewall, the owner confirms this question. However, when using the command on the wall to view (in this case telnet to 71), there is no port 23 session to 71, see Annex 1
4 The next day I used tracert 10.91.107.71 and found no IP that went through the firewall at all. See Annex 2
5 The owner provides another flying tower firewall after configuring the strategy successfully. see Annex 3
Attachment: down.51cto.com/data/2368691