User Has Been Denied From Access Internet, But IAM Doesn’t Generate Any Reject Log

|
  • 173
  • 6

Issue Description

User has been denied from access Internet, but in Internet activity doesn’t generate any reject logs.

Handling Process

  • View the access control related to the user, in the application, user has select all application and the action is reject.
  • During the testing, the access control policy is take effect, user unable to browser web page and the application unable establish the connection, but in Internet Activities doesn’t has any reject log.
  • Check the user access control again, found user has create the service policy, and the destination was select All. In IAM service policy, if the port has been reject by IAM will not generate any logs and priority of service policy is higher than application control policy.
  • Disable the service policy and IAM able to generate reject logs.


Root Cause

In IAM service policy, if the port has been reject by IAM will not generate any logs and priority of service policy is higher than application control policy.

Solution

Without doing the service policy, and only do application control policy, IAM will generate the related reject logs.
Faisal Posted 17 Aug 2020 06:58
  
Thank you very much for the information ...
Faisal Posted 26 Oct 2020 08:31
  
Nice article ...
Faisal Posted 14 Dec 2020 08:08
  
Great info ...
Ellechar Lv4Posted 01 Feb 2021 16:22
  
Very nice infoooooooooooooooooooooooooooooo
Faisal Posted 16 Mar 2021 07:14
  
Very informative …
Faisal Posted 01 Jun 2021 12:33
  
Nice guidance ...

I want to write a case
Doc ID: 2376
Author: Sangfor_SY
Updated: 2019-12-23 15:19
Version: