Access Policy Not Take Effect

|
  • 93
  • 7

Issue Description

Customer said he has configured a access policy to reject user to access a website,but he can still access it.

Handling Process

1.Check how customer configured access policy.
2.Check how customer test access policy validly.
3.Try to access https://www.tmall.com and find it can not browser https://www.tmall.com.This means the access policy is actually take effect.
4.Capture packet and find PC can establish three-way handshake,if three-way handshake was established,the telnet command  will think it could be accessed.

Root Cause

1.If three-way  handshake was established,telnet command will think the connect is established,telnet command do not identfy data segment.
2.IAM identify application by data segment rather than  three-way  handshake,the segment of three-way handshake is not enough to differentiate application,most three-way handshake packet are SYN,SYN+ACK,ACK,there’s no difference between those three-way handshake packet. enough to differentiate application,most three-way handshake packet are SYN,SYN+ACK,ACK,there’s no difference between those three-way handshake packet.

Solution

This  phenomenon  is normal,IAM can reject website in fact.
Faisal Posted 16 Aug 2020 10:34
  
Thank you very much for the information ...
Muhammad Bilal Lv4Posted 22 Aug 2020 02:03
  
Thank you very much for the information .
Faisal Posted 27 Oct 2020 10:52
  
Nice article ...
Faisal Posted 12 Dec 2020 08:47
  
Great info ...
Ellechar Lv4Posted 02 Feb 2021 09:13
  
Very nice infooooooooooooooooooooooooooooo
Faisal Posted 14 Mar 2021 07:36
  
Very informative …
Faisal Posted 30 May 2021 10:41
  
Nice guidance ...

I want to write a case
Doc ID: 2342
Author: God
Updated: 2019-12-23 15:37
Version: