Endpoint Protection

 View Only
Expand all | Collapse all

block social web with sepm 12.1

Migration User

Migration UserSep 13, 2012 09:51 AM

Migration User

Migration UserSep 14, 2012 12:25 PM

Migration User

Migration UserSep 17, 2012 12:21 PM

Migration User

Migration UserSep 17, 2012 12:23 PM

  • 1.  block social web with sepm 12.1

    Posted Sep 12, 2012 11:46 AM

     

     

    hi!

    i need to know how to block some web pages with sepm 12.1.

    i have ISA server 2004 but some users run the internet explorer/firefox with a user password that have acceses to facebook, (run as).

    So i want to use the sempm 12.1 to block that.

    I tried some of your articles and have had no luck.

     



  • 2.  RE: block social web with sepm 12.1

    Posted Sep 12, 2012 11:49 AM

    Hello,

    A Quick Note: It is important to have the Application and Device control and Firewall Installed on each Client machine. 

    Here are few Articles for the same:

    How to Restrict Users to Specific Web Sites by Creating Firewall Rules for Managed Clients
     
     
    How to block all website and allow only certain websites using Network Threat Protection Firewall rule.
     

     

    There are few Threads on the same issue as well, I would suggest a quick look into the same.

    https://www-secure.symantec.com/connect/forums/custom-ips-signature-website-blocking

    https://www-secure.symantec.com/connect/forums/how-block-access-specific-websites-both-url-and-ip-address

    https://www-secure.symantec.com/connect/forums/website-blocking-custom-ips-signatures

    Check this thread

    https://www-secure.symantec.com/connect/forums/blocking-websites

     



  • 3.  RE: block social web with sepm 12.1

    Broadcom Employee
    Posted Sep 12, 2012 02:21 PM

    Hi,

    Check this video:

    Allow and Block websites using Symantec Endpoint Protection Firewall

    http://www.symantec.com/connect/videos/allow-and-block-websites-using-symantec-endpoint-protection-firewall 

    Article: How firewall works

    http://www.symantec.com/docs/HOWTO55054



  • 4.  RE: block social web with sepm 12.1

    Posted Sep 12, 2012 05:21 PM

    thanks!
    before i create the discussion i see this video and web pages

     

    http://www.symantec.com/tv/community/details.jsp?vid=598138590001

    http://www.symantec.com/business/support/index?page=content&id=TECH92405&actp=search&viewlocale=en_US&searchid=1323777286693

    http://www.symantec.com/business/support/index?page=content&id=TECH92097&locale=en_US

    and this one: http://service1.symantec.com/SUPPORT/ent-security.nsf/2326c6a13572aeb788257363002b62aa/9c561a4628b3c9a44925747f007b19cd?OpenDocument  make a notification but doesn't work.

    none of this worked.

     

     



  • 5.  RE: block social web with sepm 12.1

    Posted Sep 12, 2012 05:27 PM

    It is very silly question to ask but at times we tend to look forget to look at small things, is NTP installed on the client?



  • 6.  RE: block social web with sepm 12.1

    Posted Sep 13, 2012 09:51 AM

    ಠ_ಠ

    of course

     



  • 7.  RE: block social web with sepm 12.1

    Posted Sep 13, 2012 10:06 AM

    hi,

    Please Check SEP Client Policy Serial no.same or not both side ?

    1. Block particular site by Symantec Endpoint protection:
    2. Choose particular Group and select policies
    3. Uncheck Inherit Policies check box
    4. Click on Firewall Policies and click on "Creat Non Shared policies from copy"
    5. Select Rules opton which on Leftside
    6. And then click on Add Rule and Click on Next
    7. Select Accroding to the requirements
    8. Select Host to Block particular site or system or Ip address
    9. Select Accroding to the requirements
    10.For Example : Here I want to block Facebook site
    11.Select DNS domain
    12. Provide the site name as below and click on next
    13. For example Type *.facebook.com and Click on Finish
    14. Rule 0 is created
    15. Select rule 0 and right click in the action column and select Block / Allow as per the requirements:
    16. To block/allow particular Port , click on Services column
    17. To block/allow any application , Click on application coloumn

     



  • 8.  RE: block social web with sepm 12.1

    Posted Sep 13, 2012 02:50 PM

    Some proposals:

    Delete IE and firefox; people could use different browsers (Chrome, Safari, Opera ...)

    In the Host column, delete all source hosts (origen) because the rule shall apply to all of them anyway ("*.*").

    Furthermore, as far as I know the DNS host entry in the Host column doesn't accept wildcards. Thus "*.*" and "*.hi5.com" don't work. However, DNS domain entries do accept wildcards, so take "*.hi5.com" as DNS domain. Change the facebook entry to "*.facebook.*" or "*.facebook*.*".

    Good luck!



  • 9.  RE: block social web with sepm 12.1

    Posted Sep 14, 2012 12:25 PM

    ok, let me work on it.



  • 10.  RE: block social web with sepm 12.1

    Posted Sep 17, 2012 09:18 AM

    its a proxy related issue? i have no luck.

    thanks for your help guys.

     



  • 11.  RE: block social web with sepm 12.1

    Posted Sep 17, 2012 10:38 AM

    SEP is not proxy aware, you will need to modify your rules to include the port your traffic is going out through.



  • 12.  RE: block social web with sepm 12.1

    Posted Sep 17, 2012 12:21 PM

    in this case 8080, nothing happen.



  • 13.  RE: block social web with sepm 12.1

    Posted Sep 17, 2012 12:23 PM

    and the client is updating the policy.



  • 14.  RE: block social web with sepm 12.1

    Posted Sep 17, 2012 01:56 PM

    Make a simplified test rule with these most important items:

    Action Application Host Service Log
    Block * All Destination: *.facebook.* * Any Write to traffic log

     

     

     

    Apply it to a test group and try if it works.

    As another possibility (but not probable), you should check if your clients are in Server Control mode or at least in Mixed control (Clients > Group > Policies > Location.specific Settings > Client User Interface Control Settings). If the clients are in Client control mode, they alone are in charge of firewall rules and the SEPM rules are ignored.