Endpoint Protection

 View Only
Expand all | Collapse all

port scan

Migration User

Migration UserMar 17, 2014 06:38 PM

  • 1.  port scan

    Posted Mar 17, 2014 06:14 PM
    somebody is scanning your computer. Your computer's UDP ports: 60213,60214,60208,54703 and 60215 have been scanned from 192.168.2.100, which is a printer on our network. Traffic Direction - Inbound


  • 2.  RE: port scan

    Posted Mar 17, 2014 06:38 PM

    Are you trying to ask a questions?



  • 3.  RE: port scan

    Posted Mar 17, 2014 06:40 PM

    Hi Brendon,

    Whats the version of SEP you are running?

    Does the printer have a setting configured which causes it to scan? I've seen this for some printers.

    This is due to the IPS policy, you can set it as an excluded host per here:

    http://www.symantec.com/docs/HOWTO81159



  • 4.  RE: port scan

    Posted Mar 17, 2014 07:26 PM

    What is the 192.168.2.100 machine? Is this on your local LAN?

    Determine what it is and if it's legit and if so, you can set it as an excluded host.



  • 5.  RE: port scan

    Posted Mar 18, 2014 10:13 AM

    I am running Version 12.1.4013.  I don't think there is any setting configured in the printer.  The printer just started printing pages with the printer owner's name on it yesterday.  I connected to the printer to troubleshoot and that is when the port scanning started. :(



  • 6.  RE: port scan

    Broadcom Employee
    Posted Mar 18, 2014 10:22 AM

    if its printer, can you check the MAC address and compare that with printer.



  • 7.  RE: port scan

    Posted Mar 18, 2014 10:25 AM

    if its printer exclude it from SEP scanning, 

    compare the ip and mac to be sure thats its indeed the printer... 



  • 8.  RE: port scan

    Posted Mar 18, 2014 10:31 AM

    The 192.168.2.100 is a printer on our local LAN.  I will check the MAC address



  • 9.  RE: port scan

    Posted Mar 18, 2014 10:37 AM

    If its legitimate ( I'm sure it is as IPS have good false positive rates) follow these steps to exclude

    1.  Open your Intrusion Prevention Policy.

    2.  Choose to Settings on the left. 

    3.  Check the box for Enable excluded hosts and then click the Excluded Hosts... button.  

    4.  Add the IP address of your printer and choose Okay.  



  • 10.  RE: port scan

    Posted Mar 18, 2014 10:48 AM

    The IP and MAC address from the port scan are the same as the printer, so it looks legitimate.  I connected the printer to the network again, and the odd printing stopped and my PC is not being scanned now.



  • 11.  RE: port scan

    Posted Mar 18, 2014 10:53 AM

    I can't seem to find a place that has a "enable excluded hosts".



  • 12.  RE: port scan

    Posted Mar 18, 2014 11:04 AM

    are you using enterprise or small business edition? its under overview sectionexclude host.PNG



  • 13.  RE: port scan

    Posted Mar 18, 2014 11:13 AM

    If the port scanning has stopped and you are no longer getting alerted, for security sake maybe excluding the printer at this time is not a good idea.  I would first try to determine why this printer was performing port scans ( is this normal behavior for this type printer...). I would leave it as is and monitor the behavior for a while.  Printers have been used as entry points into networks before.  

    Just my 2cents.



  • 14.  RE: port scan

    Broadcom Employee
    Posted Mar 18, 2014 11:27 AM

    Hi,

    Thank you for posting in Symantec community.

    Some printer communications are over UDP using raw mode. If the printer sends too many UDP packets within a set time period, the UDP Flood Attack detection is triggered. 

    To resolve the issue you will need to disable Denial of Service detection within your Instrusion Prevention policy or you will need to add the printer's IP address in "Excluded Hosts."

    To add the printer to "Excluded Hosts":

    1.  Open your Intrusion Prevention Policy.

    2.  Choose to Settings on the left. 

    3.  Check the box for Enable excluded hosts and then click the Excluded Hosts... button.  

    4.  Add the IP address of your printer and choose Okay

     



  • 15.  RE: port scan

    Posted Mar 18, 2014 11:35 AM

    I don't think I will exclude the printer just yet.  I agree that I should just wait and see what happens next.