How to configure Symantec Endpoint Protection 12.1 for use with Microsoft's DirectAccess
| Article:HOWTO55829 | | | Created: 2011-06-30 | | | Updated: 2013-04-16 | | | Article URL http://www.symantec.com/docs/HOWTO55829 |
To allow DirectAccess (DA) to function properly, please ensure that Symantec Endpoint Protection 12.1 RU2 MP1 or above is in use and enable the Windows Firewall through the SEP firewall policy using these steps:
- Log on to the Endpoint Protection Manager (SEPM).
- Click Policies.
- Click Firewall then click Edit Policy.
- Click Windows Integration.
- Select either Restore if Disabled or No Action from the Disable Windows firewall drop down menu.
If the option “No Action” is chosen, the MS FW will have to be enabled in alternate way (if it is disabled).
DirectAccess should now function as expected.
Note: In SEP 12.1, you will need to add a rule to allow Ethernet protocols 0x8100, 0xfb33, 0xfb34, 0x806 and 0x0. Also IPv6 is blocked by default, this needs to be changed to allow.
Example:
- Log on to the Endpoint Protection Manager (SEPM).
- Click Policies.
- Click Firewall then click Edit Policy.
- Click Rules.
- Select Add Rule...
- Enter a rule name
- Click Next
- Select Allow connections
- Click Next
- Select All Applications
- Click Next
- Select Any computer or site
- Click Next
- Select Only the communications selected below:
- Click Add...
- Set the Protocol to Ethernet
- Enter in the desired ethernet protocols described above
- Ensure each newly added ethernet protocol is checked
- Click Next
- Choose your desired log setting
- Click Finish
- Click OK
|
|
Article URL http://www.symantec.com/docs/HOWTO55829
Terms of use for this information are found in Legal Notices









Thank you.