Endpoint Protection Small Business Edition

 View Only
  • 1.  endpoint protection not blocking email

    Posted Sep 13, 2010 07:58 AM

    Hi everyone.  I have downloaded the trial SEP for review and testing, and am having a problem with the firewall.  I cannot get the endpoint protection software to block an application that I wrote that sends out email.  Also, I have Eudora for email purposes, and I cannot get endpoint protection to block that application as well.  I have set up my client to be in total control of the NTP segment, blanked out my application list and also all firewall rules.  Then I added a few rules, block all IP, block all TCP, and even some rules blocking TCP port 110, and port 25.  All rules created log any traffic.  I cannot get SEP to block the email program, and not only that, if I create one single rule, allow all traffic and log, I can't even get the emailing software to show up in the traffic or packet logs.  What am I doing wrong?  Please be aware that I can successfully configure FTP rules in SEP, which correctly block and log any ftp traffic that I attempt - so I know the firewall portion does in fact work.  (also when block all is in effect, internet explorer doesn't work, etc - which is correct )

    Also, I have run wireshark to verify what ports I am using within the emailing software, but that really shouldn't matter once you use a "block all IP traffic rule", should it???

    I have this feeling that I am missing something, what is it?



  • 2.  RE: endpoint protection not blocking email

    Posted Sep 13, 2010 08:39 AM

    Restart your client once and see....



  • 3.  RE: endpoint protection not blocking email

    Posted Sep 13, 2010 08:46 AM

    The screen shot of rules which you have created?



  • 4.  RE: endpoint protection not blocking email

    Posted Sep 13, 2010 01:21 PM

    Hi thanks very much for the replies.  Yes I have tried restarting the client, complete workstation etc.  Attached are some screen shots. Note that although the application rule does allow internet explorer, when I open up IE it does not work.  This is as expected of course firewall rules override application settings.

    As you can see there is only one rule, block everything!  Now, if I open up a command prompt, and try and telnet or ftp into something, the firewall kicks in, asking to give the application permission to do this.  However, when I start up eudora, there are no prompts or blocks, or anything - the email software just happily sends and retrieves email as if there was no firewall.

    -Jerry



  • 5.  RE: endpoint protection not blocking email

    Posted Sep 13, 2010 01:53 PM

    have you tried blocking 110 and 25 in an additional rule.



  • 6.  RE: endpoint protection not blocking email

    Posted Sep 14, 2010 04:36 AM

    Just for testing can you uninstall email components?