Endpoint Protection

 View Only
Expand all | Collapse all

Symantec Endpoint Protection client detected Aten KVM switch ARP MAC attack

ℬrίαη

ℬrίαηNov 05, 2013 09:04 PM

Migration User

Migration UserNov 08, 2013 10:39 PM

Migration User

Migration UserNov 09, 2013 08:45 PM

  • 1.  Symantec Endpoint Protection client detected Aten KVM switch ARP MAC attack

    Posted Oct 30, 2013 01:39 AM
      |   view attached

     Hi all,

    We have problem on Aten KVM switch (KN2140v Version 1.6.152), our Symantec Endpoint Protection client detected ARP MAC spoofing attack from this KVM. In this case, sometime will blocked some traffic that caused our IT staffs cannot login by Win client.

    Please take a look on attached screenshot, this is Symantec Endpoint Protection client offen pop-up this attack message, the 172.17.128.250 is KVM IP address.

    We think that KVM can't infected virus, right? also can you give us some solution to prevent this problem?

    Thanks



  • 2.  RE: Symantec Endpoint Protection client detected Aten KVM switch ARP MAC attack

    Posted Oct 30, 2013 01:47 AM

    Check this articles

    How to use Symantec Endpoint Protection Manager to add an exception for Intrusion Prevention Policy

     

    Article:TECH97176 | Created: 2009-01-02 | Updated: 2013-09-03 | Article URL http://www.symantec.com/docs/TECH97176

     



  • 3.  RE: Symantec Endpoint Protection client detected Aten KVM switch ARP MAC attack

    Posted Oct 30, 2013 09:26 PM

    Hello James007,

    After read your article, I don't know which Intrusion Prevention ID I need to add into exceptions list, can you help ?

    Thanks



  • 4.  RE: Symantec Endpoint Protection client detected Aten KVM switch ARP MAC attack

    Posted Oct 30, 2013 09:41 PM

    What SEP version are you running?

    This is from the anti-mac spoofing feature.

    What this feature does is:

    Allows inbound and outbound ARP (Address Resolution Protocol) traffic only if an ARP request was made to that specific host. It blocks all other unexpected ARP traffic and logs it in the Security Log.

    Media access control (MAC) addresses are hardware addresses that identify the computers, the servers, and the routers. Some hackers use MAC spoofing to try to hijack a communication session between two computers. When computer A wants to communicate with computer B, computer A may send an ARP packet to computer B.

    Anti-MAC spoofing protects a computer from letting another computer reset a MAC address table. If a computer sends an ARP REQUEST message, the client allows the corresponding ARP RESPOND message within a period of 10 seconds. All client rejects all unsolicited ARP RESPOND messages.
     

    This is in the firewall policy and you can disable if you know it is a false positive

    http://www.symantec.com/docs/HOWTO81160



  • 5.  RE: Symantec Endpoint Protection client detected Aten KVM switch ARP MAC attack

    Posted Oct 30, 2013 09:44 PM

    HI,

    Check this

    Anti-MAC spoofing enabled on RU5 blocks access to router (x.x.x.1 IP address) with "Error: Unsolicited incoming ARP reply detected, this is a kind of MAC spoofing that may consequently do harm to your computer."

     

    Article:TECH96608 | Created: 2009-01-07 | Updated: 2011-06-08 | Article URL http://www.symantec.com/docs/TECH96608

     



  • 6.  RE: Symantec Endpoint Protection client detected Aten KVM switch ARP MAC attack

    Posted Oct 31, 2013 04:49 AM

    Hello all,

    I hae Remove the check mark from "Enable Anti-MAC spoofing", but this issue still here, please help.

     



  • 7.  RE: Symantec Endpoint Protection client detected Aten KVM switch ARP MAC attack

    Posted Oct 31, 2013 05:13 AM

    Hi,

    Is't Windows 7 or Vista ?

    Try to disable Ip v6 .



  • 8.  RE: Symantec Endpoint Protection client detected Aten KVM switch ARP MAC attack

    Posted Oct 31, 2013 05:37 AM

    Hi James007,

    Our office most is using Windows 7, what do you mean disable ip v6 ? 

     

    THanks 



  • 9.  RE: Symantec Endpoint Protection client detected Aten KVM switch ARP MAC attack

    Posted Oct 31, 2013 06:13 AM

    Check Brian and Ajit comments in this thread

    https://www-secure.symantec.com/connect/forums/constant-notification-traffic-has-been-blocked-application-svchostexe

     Turn off the iphelper service, set to manual.  This stops the warning dialog from popping up.  

    2. Open the Network and Sharing Center, click "Change adapter settings", select the adapter being used, right-click and select "Properties".
    Uncheck the box next to "Internet Protocol Version 6 (TCP/IPv6)". 
    IPv6 is on by default in Vista/Win7.

    3. Restart machine.



  • 10.  RE: Symantec Endpoint Protection client detected Aten KVM switch ARP MAC attack

    Posted Oct 31, 2013 09:22 PM

    Hi James,

    Why uncheck the "Internet Protocol Version 6 (TCP/IPv6)" will unblock the KVM ip address ? I don't understand, thanks.
     



  • 11.  RE: Symantec Endpoint Protection client detected Aten KVM switch ARP MAC attack

    Posted Nov 05, 2013 08:56 PM

    Hi all,

    After disabled "Enable Anti-MAC spoofing", I don't see the message pop-up in this few days and we can remote to the KVM.

    We have a question, any option can exclude the KVM ip address in "Enable Anti-MAC spoofing" ?

     

    Thanks



  • 12.  RE: Symantec Endpoint Protection client detected Aten KVM switch ARP MAC attack

    Posted Nov 05, 2013 09:04 PM

    Can't exclude. It's either all or nothing.



  • 13.  RE: Symantec Endpoint Protection client detected Aten KVM switch ARP MAC attack

    Posted Nov 08, 2013 10:39 PM

    Do you need more help here?



  • 14.  RE: Symantec Endpoint Protection client detected Aten KVM switch ARP MAC attack

    Posted Nov 09, 2013 08:45 PM

    Hi James

    No, thanks.



  • 15.  RE: Symantec Endpoint Protection client detected Aten KVM switch ARP MAC attack
    Best Answer

    Posted Nov 09, 2013 10:01 PM

    Please Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.



  • 16.  RE: Symantec Endpoint Protection client detected Aten KVM switch ARP MAC attack

    Posted Nov 09, 2013 11:03 PM

    This is not a good solution. Please mark the one that actually helped.

    Thanks