Video Screencast Help
Symantec to Separate Into Two Focused, Industry-Leading Technology Companies. Learn more.

firewall rule

Created: 09 Mar 2013 • Updated: 26 Apr 2013 | 5 comments
This issue has been solved. See solution.

create a firewall rule in sep to block any site.
share the best solution.

Comments 5 CommentsJump to latest comment

consoleadmin's picture

try the article

https://www-secure.symantec.com/connect/articles/how-block-internet-address-sep-manager-firewall-rule

Symantec Endpoint Protection Manager - Firewall - Policies explained

Article:TECH104433  |  Created: 2008-01-20  |  Updated: 2010-11-30  |  Article URL http://www.symantec.com/docs/TECH104433

Thanks.

SOLUTION
Brɨan's picture

Follow this:

How to Restrict Users to Specific Web Sites by Creating Firewall Rules for Managed Clients

Article:TECH92097 | Created: 2009-01-28 | Updated: 2011-01-19 | Article URL http://www.symantec.com/docs/TECH92097

Please click the "Mark as solution" link at bottom left on the post that best answers your question. This will benefit admins looking for a solution to the same problem.

Sumit G's picture

Best Practises for Firewall Policy

https://www-secure.symantec.com/connect/blogs/best-practises-firewall-policy

Check the forum

https://www-secure.symantec.com/connect/forums/block-particular-website

http://service1.symantec.com/SUPPORT/ent-security.nsf/2326c6a13572aeb788257363002b62aa/9c561a4628b3c9a44925747f007b19cd?OpenDocument

How to block/allow website access using the Symantec Endpoint Protection Manager custom Intrusion Prevention Signature policy

http://bit.ly/uLiS84

Video: Allow and Block websites using Symantec Endpoint Protection Firewall

https://www-secure.symantec.com/connect/videos/allow-and-block-websites-using-symantec-endpoint-protection-firewall

Article: How To Block Internet address via Sep Manager Firewall Rule

https://www-secure.symantec.com/connect/articles/how-block-internet-address-sep-manager-firewall-rule

Blocking a Website using Symantec Endpoint Protection

Article:TECH92405 | Created: 2009-01-16 | Updated: 2012-08-22 | Article URL http://www.symantec.com/docs/TECH92405

Regards

Sumit G.

Mithun Sanghavi's picture

Hello,

Follow these steps as you do not want the users to visit to any website except for certain sites no matter what browser they use.

Solution

The above configuration can be done by creating only 2 firewall rules. Please follow the below steps to configure the rules.

1. Go to Firewall policy > Rules.

2. Click on Add Rule button. Select Host > Next > From Address Type drop down menu select DNS domain.

3. Select DNS Domain as *.* then Click Next > Click Finish.

4. Once the rule is created, highlight the New Rule. Go to Service column, right click and edit, then select Add. The rule will be TCP, Source/destination with remote port 80,443 click ok and ok again. Then go to Action column and make it set to "Block".

The above rule is to block all the websites. To create a rule to allow only selected websites, please follow the steps below.

1. Go to firewall policy> Rules.

2. Click on Add Rule. Select Host > Next > From Address Type drop down menu select DNS domain.

3. Enter DNS Domain as *.*symantec*.* This is an example which means all the urls related to symantec will be allowed.

4. Click Next > Click Finish. Multiple websites can be added to the same rule.

5. Once the rule is created, highlight the new rule. Go to Action column and make it to Allow.

Note: Place the "Allow" rule on top of "Block" rule.

Assign the policy to the required group. This will allow only the selected website and block all other website.

Caution: If the above rule is applied to the SEPM itself, we need to allow Symantec domain in order to run the liveupdate. This should be applicable to all the machine where Liveupdate will run.

Plaese find the article and let me know.

https://www-secure.symantec.com/connect/articles/how-block-internet-address-sep-manager-firewall-rule

1) How to block/allow website access using the Symantec Endpoint Protection Manager custom Intrusion Prevention Signature policy

http://bit.ly/uLiS84

2) Video: Allow and Block websites using Symantec Endpoint Protection Firewall

https://www-secure.symantec.com/connect/videos/allow-and-block-websites-using-symantec-endpoint-protection-firewall

3) Article: How To Block Internet address via Sep Manager Firewall Rule

https://www-secure.symantec.com/connect/articles/how-block-internet-address-sep-manager-firewall-rule

Hope that helps!!

Mithun Sanghavi
Senior Consultant
MIM | MCSA | MCTS | STS | SSE | SSE+ | ITIL v3

Don't forget to mark your thread as 'SOLVED' with the answer that best helped you.