Endpoint Protection

 View Only
  • 1.  Traffic.log shows no details

    Posted Feb 09, 2012 09:40 AM
      |   view attached

    Hi

    We are using SEP11. Client use version 11.06300. Clients are managed Clients...

    For some reason the traffic.log don't show any details of the blocked content, no IP address, port or nothing.... How can that be ?

     



  • 2.  RE: Traffic.log shows no details

    Posted Feb 09, 2012 10:32 AM

    This may be an "ARP Probe" or request packet.

    Looks like those MAC addresses are registered to Cisco devices. You may have an improperly configured device running IPv6 or other protocol.



  • 3.  RE: Traffic.log shows no details
    Best Answer

    Trusted Advisor
    Posted Feb 09, 2012 11:24 AM

    Hello,

    IPv6 is being blocked, which is one of the default rules in the firewall. 

    IPv6 is on by default in Vista/Win7.

    You can turn off IPv6 on your machine if it is not being used (I doubt it is) or if it is, you can turn off logging on this rule.

    I highly doubt you need IPv6 just yet. You can certainly check with your ISP for verification and to see if they have started moving to IPv6 addressing.

    You can also run an ipconfig on your machine. If you see an IP address under IPv4 then you are using IPv4 and can turn IPv6 off.

    Since IPv6 is on, it will be checked to see if it can be used and if not, it will just use IPv4.

    I don't why the default rule is to block IPv6. Probably, because it is not in widespread use yet and can cause some issues with machines/networks so Symantec took the liberty to block by default.

    Also, there should a rule ( default --> block IPV6) traffic, I assume that's causing the logs. You may verify the logs and its rule associated with..