Android Classic Profile - Samsung Knox Firewall not successfully applying over Data connection

E
Evan
DataWorks Plus

I am testing the firewall configuration in the Android Classic Profile, and I am having a problem with the cellular data restriction not applying correctly. I am testing by restricting all network traffic on both WIFI and Cellular for the google Chrome application. I have outlined the process I used below along with screenshots for reference

1. screenshot below displays the rule configuration in MobiControlFirewallRuleConfig
2. screenshot below shows that the profile was successfully installed to the device


3. screenshot below shows in the Deployment server logs that the Knox Firewall rule is being pushed to the device


4. writeprivatestring_FirewallCommand.png shows the specific MobiControl script commands that are being pushed to the device


5. screenshot below shows the commandin logcat on the android phone the IPTables command being run on the device.

6. logcat_enableFirewallFailed.png - shows the line in logcat on Android where it says "Enable Firewall failed"

I have verified that the rules I am using successfully restrict traffic on a WIFI network, but for some reason, they do not work over a cell connection (I am using Verizon Wireless)

I have tested on a Samsung J3 and a Samsung S21 using the Samsung ELM agent along with varying OS versions and Samsung Knox versions and I get the same result.

Can someone help with figuring out why the firewall rule will not apply over a cellular connection?

3 years ago
SOTI MobiControl
ANSWERS
I
ICMOD@SOTI
3 years ago

Hi Evan,

Thanks for your post!

I have a couple to questions:

1. What OS versions did you try this on?

2. Did you trying selecting Cellular instead of All?

3. What Mobicontrol version is this?

4. Is this a server on-premise or cloud?

5. Is it only chrome you tried restricting traffic?

Kind regards, 

Technical Support | SOTI Inc. | 1.905.624.9828 | support@soti.net | www.soti.net

E
Evan
3 years ago

1. What OS versions did you try this on? - OS 9, 10, 11 and 12

2. Did you trying selecting Cellular instead of All? - I did, same result

3. What Mobicontrol version is this? - 15.5

4. Is this a server on-premise or cloud? - On prem server.

5. Is it only chrome you tried restricting traffic? - I have only attempted restricting traffic on Chrome so far

I
ICMOD@SOTI
3 years ago

Hi Evan,

Thanks for your response!

Please allow me sometime to test, and check internally with the team here to see if we can offer any suggestions.

Regards,  

Technical Support | SOTI Inc. |1.905.624.9828 | support@soti.net | www.soti.net |

E
Evan
3 years ago

Hello,

Have you been able to find out any more information?

I
ICMOD@SOTI
3 years ago

Hi Evan,

Can you try restricting traffic to another application other than chrome? 

Kind Regards,

Technical Support | SOTI Inc. |1.905.624.9828 | support@soti.net | www.soti.net |