Firewall rules present but traffic still blocked

Minimal guidance for messy support realities.

Scenario

Rules exist on the firewall, but app traffic still fails between two networks.

Recommended Resolution Path

  1. Review rule order, interface placement, and NAT interactions rather than only rule presence.
  2. Capture traffic on ingress and egress to see whether the session returns.
  3. Check whether application control, IDS, or geo policies supersede the firewall rule.
  4. Verify the source and destination are the addresses you think they are after NAT.

Technician Notes

Confirm the business impact, document the root cause, and capture any preventative follow-up in the PSA or client knowledge base.