Endpoint Protection Small Business Edition

 View Only
Expand all | Collapse all

SEP/SEPM 12.1.X -Firewall exception for Port scan

Migration User

Migration UserAug 09, 2013 01:21 PM

Migration User

Migration UserAug 09, 2013 01:21 PM

  • 1.  SEP/SEPM 12.1.X -Firewall exception for Port scan

    Posted Aug 08, 2013 06:18 PM

    Hello all

    We have client running on SEPM 12.1.3 Small Business edition and SEP 12.1.1 Small Business Edition

    One of the client is repeatdly getting alerts /pop ups from SEP about a blocked port scan and upon further inspection found that this port scan is coming from a local IP assigned to a HP printer

    All firewall settings on SEP is disbled by SEPM policy.

    Do let us know how we can add an exception so that attempts from the HP printer which are getting registered as  as port scans will be ignored.

    Thanks

    Dhanushka 



  • 2.  RE: SEP/SEPM 12.1.X -Firewall exception for Port scan

    Posted Aug 08, 2013 06:34 PM

    Does the printer have a setting configured which causes it to scan? I've seen this for some printers.

    This is due to the IPS policy, you can set it as an excluded host per here:

    http://www.symantec.com/docs/HOWTO81159

    However, if you're running SBE, I can't quite recall if this feature is available but you can verify following the link I posted.



  • 3.  RE: SEP/SEPM 12.1.X -Firewall exception for Port scan

    Broadcom Employee
    Posted Aug 08, 2013 10:56 PM

    please post the image of the the message.



  • 4.  RE: SEP/SEPM 12.1.X -Firewall exception for Port scan

    Posted Aug 09, 2013 02:40 AM

    Hello Brian and Pete

    Many thanks for your posts

    Brian, unfortunatly such option is not available under intrusion prevention on SEPM SBE  edition.Please refer the attachment "Intrusion Prevention settings" for the available options.

    Pete , have attached a screenshot (Port scan-screenshot) of the pop up message.

     

    Regards

    Dhanushka



  • 5.  RE: SEP/SEPM 12.1.X -Firewall exception for Port scan

    Trusted Advisor
    Posted Aug 09, 2013 06:07 AM

    Hello,

    As this is SEP SBE version, there are limited features available.

    Could you try installing the latest SEP version?

    Latest SEP client version is SEP 12.1 RU3 (12.1.3001.165)

    Hope that helps!!

     



  • 6.  RE: SEP/SEPM 12.1.X -Firewall exception for Port scan

    Posted Aug 09, 2013 09:42 AM

    Hi Mithun

    Unfortunately even 12.1.3 does not have such options.

    Dhanushka



  • 7.  RE: SEP/SEPM 12.1.X -Firewall exception for Port scan

    Posted Aug 09, 2013 10:02 AM

    That was my worry that it was not available in SBE.



  • 8.  RE: SEP/SEPM 12.1.X -Firewall exception for Port scan

    Posted Aug 09, 2013 11:07 AM

    Does this means that there is no option to add an exception to SEP intrusion prevention / firewall ?

    Dhanushka



  • 9.  RE: SEP/SEPM 12.1.X -Firewall exception for Port scan

    Posted Aug 09, 2013 11:41 AM

    You could turn of the option to block the attacker. It will just be logged instead of actually being blocked.



  • 10.  RE: SEP/SEPM 12.1.X -Firewall exception for Port scan

    Posted Aug 09, 2013 11:47 AM

    Based on what I see on SBE editions its only possible to disable port scans completly.

    But this option is locked on SEP.How can we unlock this option?

    Also is it possible to disable only the port scan notifications?

    Dhanushka



  • 11.  RE: SEP/SEPM 12.1.X -Firewall exception for Port scan

    Posted Aug 09, 2013 12:12 PM

    Go into the Firewall policy >> Protection and Stealth tab and uncheck Automatically block an attacker's IP address.

    To disable the notification, check this:

    How to Disable Client Intrusion Prevention Notifications in Symantec Endpoint Protection Manager (SEPM)

    http://www.symantec.com/docs/TECH105013



  • 12.  RE: SEP/SEPM 12.1.X -Firewall exception for Port scan

    Posted Aug 09, 2013 12:29 PM

    Hi Brian

    Unfortunately there is no such option on SBE 

    Dhanushka



  • 13.  RE: SEP/SEPM 12.1.X -Firewall exception for Port scan

    Posted Aug 09, 2013 12:32 PM

    Do you have the firewall policy withdrawn completely from the client?



  • 14.  RE: SEP/SEPM 12.1.X -Firewall exception for Port scan

    Posted Aug 09, 2013 12:35 PM

    Havent done any changes to the client.Its still in the same group with all the policies applied like before.

     



  • 15.  RE: SEP/SEPM 12.1.X -Firewall exception for Port scan

    Posted Aug 09, 2013 12:38 PM

    If you're not using the firewall policy than you can withdraw it completely

    http://www.symantec.com/docs/HOWTO80907



  • 16.  RE: SEP/SEPM 12.1.X -Firewall exception for Port scan

    Posted Aug 09, 2013 01:21 PM

    Should be corrected as SBE



  • 17.  RE: SEP/SEPM 12.1.X -Firewall exception for Port scan

    Posted Aug 09, 2013 01:21 PM

    Again , there is no withdraw option on SBB :(

     



  • 18.  RE: SEP/SEPM 12.1.X -Firewall exception for Port scan
    Best Answer

    Trusted Advisor
    Posted Aug 10, 2013 05:05 AM

    Hello,

    That's what I meant, in SEP SBE version there are limited features available.

    In other words, this feature of creating exceptions OR removing the notification is not available.

    In your case, you could simply disable the Intrusion Prevention policy from the SEPM SBE 12.1

    OR

    Deploy the package on the client machine without IPS feature.

    Hope that helps!!



  • 19.  RE: SEP/SEPM 12.1.X -Firewall exception for Port scan
    Best Answer

    Broadcom Employee
    Posted Aug 10, 2013 05:19 AM

    can you create  a new policy for firewall and IPS and check if it gets suppressed.



  • 20.  RE: SEP/SEPM 12.1.X -Firewall exception for Port scan

    Posted Aug 12, 2013 04:48 AM

    Have created a new group/firewall policy and addedd the MAC address of the printer and allowed all connections from that MAC address.

    Added the client is question to the group.

    Will monitor for a couple of days and get back with an update.

    Dhanushka

     



  • 21.  RE: SEP/SEPM 12.1.X -Firewall exception for Port scan

    Posted Aug 16, 2013 09:05 AM

    Sorry for the delay but had to attend to few other urgent issues.Will give an update as soon as possible

    Dhanushka



  • 22.  RE: SEP/SEPM 12.1.X -Firewall exception for Port scan

    Posted Aug 20, 2013 02:01 PM

    Hello all

    Got the feedback from the cleint today and the popup is no more!!!!

    Thanks all for your time and support on this issue.

    Regards

    Dhanushka