Endpoint Protection

 View Only
Expand all | Collapse all

how to find more information about exactly what is being blocked??

  • 1.  how to find more information about exactly what is being blocked??

    Posted Jan 09, 2015 02:56 PM

    We recently set up a Spiceworks server and it is trying to scan/probe the servers.

    SEP is giving this response back, shown in this image:

    sep-Capture.PNG

    Where/how do I find in the SEPM Manager what ports SEP thinks it's being attacked on and how to enable them for this specific server IP of the Spiceworks server??

    Thank you, Tom



  • 2.  RE: how to find more information about exactly what is being blocked??

    Posted Jan 09, 2015 03:19 PM

    thats from IPS, 

    Go to IPS there is an option to uncheck this or create a exclusion for your server.

    http://www.symantec.com/business/support/index?page=content&id=TECH116730



  • 3.  RE: how to find more information about exactly what is being blocked??

    Posted Jan 09, 2015 03:25 PM

    Apologies, thats from Firewall rules,

    open sepm

    open firewall policies there an option to block attackers IP, if thats your server IP, you can uncheck that or create a rule to allow it.firewall.PNG



  • 4.  RE: how to find more information about exactly what is being blocked??

    Posted Jan 09, 2015 03:30 PM

    This info shows in the Security log



  • 5.  RE: how to find more information about exactly what is being blocked??

    Posted Jan 12, 2015 10:04 AM

    In SEPM, you will find the log under Monitors > Logs > Network Threat Protection > Attacks > Event Type: Port Scan



  • 6.  RE: how to find more information about exactly what is being blocked??

    Posted Jan 13, 2015 02:56 PM

    I don't want to turn off that protection setting.

    I do want to exclude the Spiceworks server IP address, where do I learn how to make a rule to do this??

    The firewall rules go by what type of traffic, not where the traffic comes from...

    Thank you, Tom



  • 7.  RE: how to find more information about exactly what is being blocked??

    Posted Jan 13, 2015 03:01 PM

    You can create a firewall rule to allow the SW IP. You either allow ALL traffic from SW or you can allow specific ports if you know them.



  • 8.  RE: how to find more information about exactly what is being blocked??

    Posted Jan 13, 2015 03:03 PM
    Please check the security logs. You will find the rule which is blocking it


  • 9.  RE: how to find more information about exactly what is being blocked??

    Posted Jan 13, 2015 03:06 PM

    Which specific one of the logs?? There's no log called 'security.' :) :)



  • 10.  RE: how to find more information about exactly what is being blocked??

    Posted Jan 13, 2015 03:06 PM

    I did this to allow all traffic in from the Spiceworks server, I'll see what happens.



  • 11.  RE: how to find more information about exactly what is being blocked??

    Posted Jan 13, 2015 03:10 PM

    If you're looking in SEPM, it's under Monitors >> Logs

    Set the log type to Network Threat Protection

    Set the log content to Attacks

    It will show as a Port Scan

    Otherwise it's on the Security log on the client itself



  • 12.  RE: how to find more information about exactly what is being blocked??

    Posted Jan 13, 2015 03:27 PM

    OIC -- I did this already, I just now found how to use the Details item to see the ports the scans were blocked on...thank you :) :)



  • 13.  RE: how to find more information about exactly what is being blocked??

    Posted Jan 13, 2015 03:30 PM

    Good deal, happy to help!