Endpoint Protection

 View Only
  • 1.  Traffic has been blocked from this application: (svchost.exe)

    Posted Jun 25, 2013 07:15 PM

    I know this has probably been brought up many times, but Ive yet to find anything to help me.

    I am using SEP 12.1.1000.157 RU1.

    Basically I want to try and find out if I have been infected by a virus or some malware, or if SEP is just going crazy. I have not been able to find logs or anything so I dont have much to post however if they are needed and someone can give me directions on where to find them, I can post them.

    I'm running Windwos 7 Home Premium 64 bit.



  • 2.  RE: Traffic has been blocked from this application: (svchost.exe)

    Posted Jun 25, 2013 07:20 PM

    It's the SEP firewall alerting on this:

    Traffic has been blocked for the application host process for Windows Services Svchost.exe

    Article:TECH165942  |  Created: 2011-07-29  |  Updated: 2012-07-28  |  Article URL http://www.symantec.com/docs/TECH165942

     

    It could be because of IPv6. This can be turned off in Windows

    One of the default firewall rules in SEP is to block this behaviour.

    If you open the firewall rules, this particular rule should be at the top. You can chose to allow it or let it continue to be blocked.

    IPv6 is not widely used so it's really up to you.



  • 3.  RE: Traffic has been blocked from this application: (svchost.exe)

    Broadcom Employee
    Posted Jun 25, 2013 09:47 PM

    check the traffic logs.



  • 4.  RE: Traffic has been blocked from this application: (svchost.exe)



  • 5.  RE: Traffic has been blocked from this application: (svchost.exe)

    Posted Jun 27, 2013 07:55 AM

    Hi

    Please refer the article below

    http://www.symantec.com/business/support/index?page=content&id=TECH165942&actp=search&viewlocale=en_US&searchid=1372334029852

    Regards

     



  • 6.  RE: Traffic has been blocked from this application: (svchost.exe)

    Posted Jul 10, 2013 07:40 AM

    Hi

    Can you please provide the update on the provided solution

    Regards

     



  • 7.  RE: Traffic has been blocked from this application: (svchost.exe)

    Posted Jul 16, 2013 05:05 AM

    Hi, 

    Have you checked the logs on SEPM related to it ?

    Keep posted the logs for further analysis.

    Regards

    Ajin



  • 8.  RE: Traffic has been blocked from this application: (svchost.exe)

    Posted Sep 16, 2013 08:20 AM

    Disabling IPv6 is NOT a good solution.



  • 9.  RE: Traffic has been blocked from this application: (svchost.exe)

    Posted Sep 18, 2013 12:48 AM

    Hi

    Can you please upgrade to SEP 12.1.3 and observe

    Regards