Endpoint Protection

 View Only
Expand all | Collapse all

iPhone Wifi Sync Blocked by SEP Firewall

alex.milford

alex.milfordDec 27, 2012 03:56 PM

ℬrίαη

ℬrίαηMar 16, 2013 08:11 AM

  • 1.  iPhone Wifi Sync Blocked by SEP Firewall

    Posted Oct 07, 2012 11:17 PM

    When I fully disable my SEP firewall, wifi sync works normally (iTunes automatically recognizes the phone on the network).  When the firewall is re-enabled, the sync fails and cannot be restarted.  How can I configure the firewall to allow this communication?



  • 2.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Oct 07, 2012 11:25 PM

    Configure Symantec Endpoint Protection for iTunes Home Sharing

    http://www.symantec.com/business/support/index?page=content&id=TECH155340



  • 3.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Broadcom Employee
    Posted Oct 08, 2012 03:17 AM

    Hi,

    Could you please check NTP traffic & Packet logs. Which rule is blocking connection?

    If possible create a firwall rule to allow the communication.

    Adding a new firewall rule

    http://www.symantec.com/docs/HOWTO55404

    About firewall rules

    http://www.symantec.com/docs/HOWTO55261



  • 4.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Oct 08, 2012 09:52 AM

    Sharing actually works, it's the wifi sync that's causing issues.  Thanks for your help!



  • 5.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Oct 08, 2012 09:57 AM

    What components do you have installed?

    System Wifi are working or not ?



  • 6.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Dec 27, 2012 03:55 PM

    I have this exact same problem. If i disable SEP it works fine. Nothing in the packet or traffic logs showing anything blocked and if i disable the FW it allows me to initiate a sync but it fails to complete



  • 7.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Dec 27, 2012 03:56 PM

    have all comppnents of SEP installed



  • 8.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Dec 30, 2012 12:08 PM

    Create a DENY_ALL rule and move it to the bottom. Than try the sync again. Something should show in the traffic log and post it here.



  • 9.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Mar 13, 2013 04:43 PM

    Greetings,

    I need more detailed advise than what is listed above. Like the other posters, I am using iTunes on my computer, and Symantec is preventing my computer from wifi syncing with my iPad.

    I uses iTunes 11, SEP 12.1, Windows 7 (64-bit) on my computer. When SEP is disabled, iTunes will see my iPad through wifi and sync through wifi. With SEP enabled, iTunes will not see my iPad through wifi or wifi sync.

    Kindly give step-by-step instruction on how to identify the blockage and eliminate it.

    Thank you.



  • 10.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Mar 13, 2013 05:25 PM

    You need to open the SEP client and open the Traffic log under Network Threat Protection. This will show what is being blocked. You can post here as well for review.



  • 11.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Mar 13, 2013 07:32 PM
      |   view attached

    Thank you. I opened the SEP client, opened iTunes, turned on my iPad, and looked at the resulting traffic report. I've attached it here. I do not know how to decipher it, but I welcome your help.

    Thank you.

    Attachment(s)

    xlsx
    iTunes.xlsx   153 KB 1 version


  • 12.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Mar 13, 2013 07:52 PM

    Did you try to sync right before posting the log? If not, can you try to sync, note the time than post?



  • 13.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Mar 13, 2013 08:01 PM

    I can't sync because iTunes doesn't detect the iPad. The only way to sync would be to use the cord to connect the iPad to the computer physically. Is that what you want me to do?

    By the way, is there any danger to posting my log results? Hacking, etc?



  • 14.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Mar 13, 2013 08:16 PM

    Yes but even an attempted sync should show up as a block in the traffic log. Than we can see exactly what is being blocked and create a rule to allow it.

    Since your IP is 192.168.x.x you should be fine. That is a NAT'd address which is standard on home routers.



  • 15.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Mar 13, 2013 09:18 PM
      |   view attached

    At 20:06 p.m. on 3/13/2013 I tried to wifi sync by touching the greyed out "Sync Now" button on the iPad. But recall that iTunes doesn't even see the iPad with SEP enabled, so touching the greyed out button did nothing. I saw nothing that suggested that even an attempt at a sync occurred.

    At 20:08 p.m. I connected the iPad cord to the computer.

    At 20:09 p.m,I touched the now-blackened "Sync Now" button on the iPad, and the sync process lasted less than a minute.

    I'm attaching the traffic log.  Does this help you?

    Attachment(s)

    xlsx
    iTunes2.xlsx   152 KB 1 version


  • 16.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Mar 13, 2013 09:31 PM
      |   view attached

    I tried something else that may help you diagnose. I disabled SEP, which allowed iTunes to detect my iPad, so that I can perform a wifi sync. Then I reenabled SEP, and since iTunes still said that it could see my iPad, I attempted a sync.

    As soon as I hit sync (3/13/2013 at  20:25), iTunes looked in vain for the iPad, and then the sync failed. And then the iPad disappeared from iTunes's sidebar.

    I'm am attaching the traffic log that might reflect this activity, but it just shows two activities that were "allowed"; nothing was blocked, so I'm not sure this helps.

     

     

    Attachment(s)

    xlsx
    iTunes3.xlsx   151 KB 1 version


  • 17.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Mar 14, 2013 11:37 AM

    Create a fw rule to allow port 5355. See if this fixes it.



  • 18.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Mar 14, 2013 04:32 PM

    Thank you. I will reveal my ignorance here. How do I create a firewall rule like that? If you don't mind giving me a step-by-step explanation, I would be grateful.

     



  • 19.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Mar 14, 2013 07:18 PM

    Just to follow-up:  I think I see how to get started:

    Status->Network Threat Protection->Options->Configure Firewall Ruels->Add

    Then I get stuck. I assume I should click "Allow" traffic in the General tab, but I don't know what to do under the other tabs, particular the Ports tab (which protocol, remote port, local port, traffic direction etc.)



  • 20.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Broadcom Employee
    Posted Mar 15, 2013 02:57 AM

    Hi,

    Check this thread: https://www-secure.symantec.com/connect/forums/sep-firewall-rules-itunes-airplayhome-sharing

    Specially Solved comment " I had created an "allow all" rule for iTunes.exe prior to starting this post. It did not suffice. After our chatter exchange, I created 2 rules for ports UDP 5353 and TCP 3689 and disabled the previously created iTunes rule. All seems to be well now."

    Check this article as well:

    http://support.apple.com/kb/TS1629



  • 21.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Mar 15, 2013 11:21 AM

    Thank you. I've read the threads and would like to try create "2 rules for ports UDP 5353 and TCP 3689" but I do not know the steps to take. I've tried to navigate around the settings but I am still perplexed. Can you assist me?

    Thank you again.



  • 22.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Mar 15, 2013 11:35 AM

    Open the SEP and under NTP options select configure firewall rules

    Click Add, give the rule a name and set the Action to Allow this traffic

    On the Hosts tab either add the IP of your ipad or your internal subnet

    On the Ports and Protocols tab select the UDP protocol and set the remote port to 5353

    You can leave Applications and Scheduling tab alone if you wish

    Click OK and move rule to the top

    Repeat for same steps for second rule



  • 23.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Mar 15, 2013 03:10 PM

    Thank you for the detail. I will try this.

    However, after reading the article you posted, http://support.apple.com/kb/TS1629, I noticed that the two ports you mention, UDP 5353 and TCP 3689, do not correspond to iTunes "wifi sync" or something like that. They correspond to iTunes Music Sharing, Airplay, Bonjour, and related iTunes programs. In the thread that you directed me to, https://www-secure.symantec.com/connect/forums/sep..., the problem was using Airplay. I don't know if that matters, but my problem is that SEP is blocking wifi sync with iTunes.

    Anyway, I will try this and report back.



  • 24.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Mar 15, 2013 07:38 PM

    Unfortunately, aftter creating FW rules to allow UDP 5353, TCP 3689, and even TCP 3004, iTunes still does not "see" my iPad and will not sync with it over wifi. I'd be grateful if you had any other ideas.



  • 25.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Mar 15, 2013 10:36 PM

    I double-checked the FW settings, and they are as you told me to set them. I left blank the option for "local port"--hope that was correct.



  • 26.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Mar 16, 2013 07:47 AM

    Than something is still being missed especially if you disable the firewall and it works.



  • 27.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Mar 16, 2013 08:01 AM

    Well, oddly enough, after I rebooted and opened and closed iTunes a few times, it's now working! According to the Apple Support Forums, many people have problems with wifi sync, and many of the fixes work for onloy a brief period, so I may encounter problems again. Many people think that the problem is inherent in iOs6 and iTunes 11. But at least for now it is working for me.

    Thank you again for your patient help!



  • 28.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Mar 16, 2013 08:11 AM

    Glad it is working.



  • 29.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Mar 16, 2013 08:13 AM

    One last (I hope) question, though: With those ports now open in the firewall, what risks to I create for my computer?



  • 30.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Mar 16, 2013 08:21 AM

    If you get infected and malware uses those ports for communication, it would be allowed out.



  • 31.  RE: iPhone Wifi Sync Blocked by SEP Firewall

    Posted Mar 21, 2013 04:04 PM

    Just a quick update. Five days later, and I have found that most of the time iTunes will recognize the iPad through wifi and sync through wifi.

    Here is what I've done that seems to enable wifi detection and syncing on my computer (note that I use Windows 7, iTunes 11, Symantec Endpoint Protection 12.1; iPad II iOS 6):

    For the iPad, I created an "allow" firewall rule on Symantec. On the Host tab I used the IP address of my iPad. For the port, I set both local and remote ports to keep open UDP port 5353.

    To enable iTunes on my computer see another, shared library residing on another computer on my home network, I created another "allow" firewall rule. On the Host tab I used the IP address of the other computer (On the other computer, go to Start, enter "cmd", then enter "ipconfig", then look for IPv4). For the port, I set local and remote to UDP port 5353. This works great.

    iTunes doesn't always see the iPad, even with Symanteic End Protection entirely disabled, so part of the problem is Apple's, not SEP. But "most of the time" is a lot better than "never." And sometimes to get iTunes to see my iPad, I have to restart the service "Apple Mobile Device."