Endpoint Protection

 View Only
  • 1.  MAC ACL Firewall rules are not working in SEP 12.1.6

    Posted Mar 01, 2016 04:00 PM

    My company is using SEP's firewall as it's main source to block users from accessing our servers.

    I'm using the attached firewall rules, but they're still not just allowing the Host's I specified to connect. I'm able to plug in a laptop not in the host list and access our servers.

     

    I would like some assistance to know if what we're trying to do is possible, or if we need to find a different solution.

     

    Thanks

    2016-03-01 12_56_07-Clipboard.png



  • 2.  RE: MAC ACL Firewall rules are not working in SEP 12.1.6

    Posted Mar 01, 2016 04:09 PM

    In addition are you getting any data showing up in the Traffic log?
     



  • 3.  RE: MAC ACL Firewall rules are not working in SEP 12.1.6

    Posted Mar 01, 2016 04:29 PM

    I do not know where to find the Traffic Log, but the policy is set up to record it.



  • 4.  RE: MAC ACL Firewall rules are not working in SEP 12.1.6

    Posted Mar 01, 2016 05:01 PM

    Open the client and go to View Logs >> Network Threat Protection >> Traffic log



  • 5.  RE: MAC ACL Firewall rules are not working in SEP 12.1.6

    Posted Mar 01, 2016 05:33 PM

    I'm getting some from one server that shows that the policy is working, but from another one in the same group, it's allowing the laptop to connect to the server.



  • 6.  RE: MAC ACL Firewall rules are not working in SEP 12.1.6

    Posted Mar 02, 2016 06:20 PM

    Are my rules set up correctly? Or do i need to change something?



  • 7.  RE: MAC ACL Firewall rules are not working in SEP 12.1.6

    Posted Mar 02, 2016 06:48 PM

    and just as a quick confirmation, the client that is allowed, did it get the updated policy/is connected to the SEPM?



  • 8.  RE: MAC ACL Firewall rules are not working in SEP 12.1.6

    Posted Mar 03, 2016 06:56 PM

    Yes, all policies are updated and the servers are connected to SEPM. They are in the same policy group, yet some servers allow connection to them while others do not.