Help understanding application behavior in policies
Hello,
This is driving me nuts and looking for some assistance. I recently set up a new policy (ID 188) and am having issues getting traffic to properly hit it and I am not sure why.
I have the two following policies configured:
Traffic matching policy 129 looks like the following:
Traffic matching policy 188 looks like the following:
On policy 188, I initially had it configured with application of 'ssl' and 'web-browsing' with service set to 'application-default' which didn't work. I then changed application to 'any' and set the services to 'tcp/443 and tcp/80' this didn't work either. I finally tried setting application to 'any' and services to 'any' and that is not working either!
It seems like maybe the initial handshake isn't completing or the firewall isn't seeing enough in the initial packet(s) to start looking further down the policy stack, but I am not sure why. I have other sites with the exact same set up using the application of 'ssl' and service of 'application-default' and those work just fine. Maybe I am just not understanding something correctly but I feel like I am going insane with this.
Thanks!