Schedule is not working in Policy Control

Fender
Fender Posts: 24  Freshman Member
First Anniversary Friend Collector First Comment
edited April 2021 in Security
Hi, I have a firewall rule WAN --> LAN with service: FTP. I only want to have that port open during business time (say 9:00 -17:00). So I made a schedule with this time frame and added i to the firewall rule. But after the time schedule the port is still open. What is going wrong?

Accepted Solution

  • Zyxel_Stanley
    Zyxel_Stanley Posts: 1,366  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Answer ✓

    Hi @Fender  

    I setup time schedule 14:00~14:15 to allow specific service from WAN to LAN.

    And it looks traffic will block after time frame.



    According to your FTP service port still alive, you may have a check if USG local FTP server is enabled or not.


All Replies

  • PeterUK
    PeterUK Posts: 2,704  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    edited December 2020
    Tested here with a USG40 V4.60 by from WAN to DMZ bridge and works fine.

    top rule allow from WAN to DMZ FTP and schedule then a rule under that to deny from WAN to DMZ FTP.

    Maybe you have another rule allowing FTP? 
  • Zyxel_Stanley
    Zyxel_Stanley Posts: 1,366  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Answer ✓

    Hi @Fender  

    I setup time schedule 14:00~14:15 to allow specific service from WAN to LAN.

    And it looks traffic will block after time frame.



    According to your FTP service port still alive, you may have a check if USG local FTP server is enabled or not.


  • Fender
    Fender Posts: 24  Freshman Member
    First Anniversary Friend Collector First Comment
    Hi Stanley, your last screenshot, the USG local FTP server was checked. So when I tried a FTP check with http://scanner.openportstats.com/ the port seemed to be open. I unchecked it now, thank you!
  • Zyxel_Stanley
    Zyxel_Stanley Posts: 1,366  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Hi @Fender
    It's good to know it helped in your case.  B)

Security Highlight