SCS 3.1.6.6010 firewall problems
Created: 26 Jul 2007 | Updated: 21 May 2010 | 2 comments
All things being equal, just updating from an older version of SCS to the current 3.1.6.6010 patched version on several of my systems, SMTP port 25 connections are being blocked, even though the three applications I've tested that send e-mail themselves are in the programs listing as Allow All. Again, all things being equal, given that this one particular system I'm working on right now has had probably 12 different versions of SCS over the past 3 years, one updated over the next, and connects to a central server for settings and updates, has never had this particular problem until after the update to 6010. To confirm it is the Symantec Firewall in play, I disabled the firewall and rebooted and the socket errors I was getting trying to send out over port 25 no longer exist.
Very strange, because these programs themselves are (and always have been) set to Allow connections from these computers, so I'm not seeing what setting change there could be to account for this change in behavior. It would seem that our systems with just build 6000 installed (3.1 MR6) are not having a problem, so it does appear to be a bug or at least a new setting change I have yet to find in build 6010 (3.1 MR6 MP1).
Discussion Filed Under:
Comments 2 Comments • Jump to latest comment
Here's what I found, after a lot of methodical testing. First, the problem only occurs when the computer is booted up, logged in, logged off (without a reboot), and logged in the second time. That's right, it is on the second login the Client Security build 6010 bug comes into play.
Since it was taking to long to test the problem with an e-mail client, I just started testing with portqry.exe to two different mail servers which accept port 25 connections. Under all proper conditions, portqry would get a "listening" response from either of the mail servers. After the second login (see above), however, portqry would no longer get a response from the mail servers, but instead was prevented from a connection. Again, the first login after boot, it has no problem, it is upon the second login the abnormal behavior is observed. This even happens when I disable the Symantec firewall, set the security setting to "manual", and reboot.
After testing all this to be able to reproduce the conditions upon the bug occurs, I uninstalled SCS build 6010, rebooted, installed build 6000, rebooted, and did my testing again. The portqry port 25 (and e-mail send) tests now work properly again, on the first, second, and third logins.
Would you like to reply?
Login or Register to post your comment.