Endpoint Threat Protection Rules

Jeremy-T's picture

Regarding Endpoint Threat Protection rules:

In dealing with applications that are not detected, for which Endpoint does not prompt for permissions, I attempted making individual firewall rules to allow them network access.
In each case they did not work. However,  if an individual firewall rule is made for applications that Endpoint would otherwise detect, the added custom rules do work.

Question is, what needs to be done to either force Endpoint to detect all applications, or otherwise force it to respect all rules, including those added for applications not detected.

Thank you,

Jeremy

Rafeeq's picture

Hi

Please check this doc

Symantec Endpoint Protection: Firewall blocking application when adding the application manually or from the learned applications list

http://service1.symantec.com/support/ent-security.nsf/854fa02b4f5013678825731a007d06af/b59baea9f152f2d8882573a6006a1d96?OpenDocument

Rafeeq

sandip_sali's picture

Firewall rules

With Mixed mode enabled for the client group. Open the Endpoint Protection Client interface and select "Options" next to "Network Threat Protection". Next click on "View Firewall Activity".

 After the Network Activity window opens, select "Tools" and click on "View Firewall Rules". This will have all the rules of the firewall policy, and the user defined rules underlined.

Thanks & Regards

Sandip C Sali

JeremyT's picture

Thanks very much for your

Thanks very much for your replies. Unfortunately however, in spite of having added every dll associated with the problem apps (as directed), Endpoint still does not allow  internet connections for them. It still allows connections only for those apps that it initially recognized and prompted for permission or no permission to connect.

Why does Endpoint not prompt for some apps? Can it be made to do so?
Frankly I see this as bug which should be corrected, as it should prompt for all applications attempting to make a connection.

Thanks

PrasadMasurkar's picture

in order to allowed full

in order to allowed full inter net access create rule as bellowed

Give Rule name as - Allowed Web Browsing --> in application select - Any & allowed port in servicesas TCP 80, 443 outging Remote.

if you want to Allowed particular Application like MSN then give Rile name as Allowed MSN then in application mention path like for MSN

C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
msnmsgr.exe
msmsgs.exe

so it will worki MSN...
 & if you want to be block MSN then just create above rule & in Action tab select Block
 so it will block your MSN

AravindKM's picture

In which log files you are

In which log files you are getting the application blocked messages?
In ntp logs or in ptp logs? 

JeremyT's picture

This post would not display my message nor my images as below.

This post would not display my message nor my images as below.
 
JeremyT's picture

NTP traffic log

1.jpg

 Connection is blocked in spite of the fact that IPv6[type-0x86DD] is configured to allow.

sandip_sali:

Following your directions, I could not find where to enable "Mixed mode" for the client group. Also, in  "Network Threat Protection", I only see  "View Network Activity' and not "View Firewall Activity". Nevertheless, I clicked on  "View Network Activity' and found that the only option on the Tools menu is "Test Network Security" and not "View Firewall Rules." As is, the only items on the list are system 32 services.

AravindKM:

The NTP logs list the app's connections blocked as you see in the images above.

AravindKM's picture

Make your client to server

Make your client to server control mode
For this login to SEPM
Go to clients Tab
Select the desired group
Click on policies on right side
Under location specific settings you can find 

  Client User Interface Control Settings

Edit it and make it as server control

Create a rule for allowing all the application which is getting blocked
Place it above the block_all rule (According to your screen shot the "block_all" rule is blocking your traffic to those application)
The rule created by you should be placed above blue line
Remember in SEPM firewall rules are getting processed from top to bottom .So the rule which is placed in top having more priority than below one

Below doc can help you in creating the policy
How to add a rule using the"Add Firewall Rule Wizard"
In firewall policy you can use move up or move down a policy by right clicking on it...

JeremyT's picture

Thank you AravindKM. I will

Thank you AravindKM. I will follow your directions.

AravindKM's picture

If you are facing problem

If you are facing problem even after this pls post a screen shot of your F/W policy.... 

JeremyT's picture

AravindKM: As a last resort

AravindKM:

As a last resort  I've sent you one of the programs which Endpoint does not allow to communicate through. Hopefullly you'll be able to test it. If it also doesn't work for you, then it will be time to move away from Endpoint and onto another security system.

Thanks

AravindKM's picture

Can you give me a scrennshot

Can you give me a scrennshot of your firewall policy?
After changing any policy in the SEPM client is geting that policy .Am i right? (you can confirm this by matching the sl . no of the policy for that group with the policy sl. no wivh is present in the client Help and support ----->troubleshooting)

AravindKM's picture

Whether your software req

Whether your software req IPv6. If not req. try by disabling it.
If it not works/not possible  check which is the rule blocking it.The last column of Traffic log will give you that information
The rule which you created for allowing this traffic place above this blocking rule...
It will be nice if you are able to provide us a screen shot of your firewall policy..

 

AravindKM's picture

An addition to my earlier post

 You can also disable the rule which find as culprit for this you have to uncheck the enabled column corresponding to the culprit rule...

JeremyT's picture

AravindKM: I'm very grateful

AravindKM:

I'm very grateful to you for all the time and interest you've taken to help me resolve this issue. However, I'm no longer able to post any other screenshots as I've moved on to evaluating another security system. It's bad enough that Endpoint does not recognize some programs and does not prompt for permissions, but manual and proper configuration doesn't work for them either. Regarding the "culprit rule," After following all your suggestions, I additionally tried setting all rules to allow, and still the manually added programs were denied a connection.

Have you tried installing the program I sent you? I would be curious to know if you're able to get it to connect through Endpoint. If you're able to, I might even take on the challenge of re-evaluating Endpoint.

Thanks again and regards,

Jeremy

AravindKM's picture

Create a allow all rule and

Create a allow all rule and make it as the first rule and try.... 

JeremyT's picture

Thanks AravindKM: Yes, I had

Thanks AravindKM:

Yes, I had tried that in addition to setting ALL other  rules on ALLOW.
Again all programs could connect to the internet except those that Endoint did not initially recognize and prompted for permissions.

AravindKM's picture

Did you restarted the pc

Did you restarted the pc after setting these policies? 

JeremyT's picture

Yes, I did restart after

Yes, I did restart after making any policy change. Thanks