Endpoint Protection

 View Only
  • 1.  Block all traffic until the firewall starts setting causing DHCP errors

    Posted Jul 25, 2012 11:42 AM

    Hi all

    After scouring the forums I have not found the solution for this problem, A similar thread looks like the same issue however was created in 2009 and is now locked with no solution:  https://www-secure.symantec.com/connect/forums/different-dhcp-problem

    The setting "Block all traffic until the firewall starts and after the firewall stops" is causing issues on several clients on my network (rougly 5%).  Clients are issues with APIPA address, as they were blocked from connecting to the DHCP server.  Event viewer logs on client clearly show:

    DHCP-client Event 1001:
    Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address xxxxxxxxxx.  The following error occurred: 0x79. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
     

    If I disable this setting on the policy we no longer experience the problem however for obvious security reason I believe it is best to enable this where possible.


    It is my understanding that the "Allow initial DHCP and NetBIOS traffic" should stop any DHCP issues using the SEP smart filter to allow DHCP requests, this clearly isnt working as intended.  I have created a firewall rule to specifically allow the DHCP service which takes effect on both clients and DHCP server however this still hasnt resolved the problem becuase all traffic is still being blocked.

    Any suggestions would be greatly appreciated.

    Thanks

     



  • 2.  RE: Block all traffic until the firewall starts setting causing DHCP errors

    Posted Jul 25, 2012 12:01 PM

    Do you have "Enable Smart DHCP" setting checked?

    Did you modify your firewall policy to allow DHCP traffic?



  • 3.  RE: Block all traffic until the firewall starts setting causing DHCP errors

    Posted Jul 25, 2012 05:36 PM

    The "Allow DHCP" firewall rule that you created isn't going to be evaluated while SEP is not running; while SEP is off, the driver is using some hardcoded rules based on those two settings and it doesn't utilize the full firewall rule set.

     

    Using wireshark to figure out exactly what is being blocked would be helpful here.

     

    There are some WPP logs on the client that would be usefull to a support engineer to troubleshoot this issue(unfortunately, these WPP logs are not human readable). If you have a support contract, it would be good to utilize that.

     

     



  • 4.  RE: Block all traffic until the firewall starts setting causing DHCP errors

    Posted Jul 26, 2012 11:53 AM

    Hi guys thanks for the quick replies,

    Yes Smart DHCP is enabled, thanks for the advice though Brian81.

    Landon, I have a support contract (somewhere, lol) I will raise a request asap thanks.

    Wireshark is beyond my abilities at the moment im afraid, its on the todo list ;)

    Cheers