Endpoint Protection

 View Only
  • 1.  which one blocks first sep firewall or sep IPS (need symantec tech. support's help)

    Posted May 15, 2009 12:52 PM
    I have configured firewall rule to block ip address 10.33.1.100 (example) for both inbound and outbound. so I think anything goes from 10.33.1.100 should be blocked by all sep clients. which is blocking also but  clients shows a message for Active response intrusion prevention stating that ip address 10.33.1.100 has been blocked by sep for 60 seconds.

    Now my question is while I have a firewall  rule applied which states that all communications from 10.33.1.100 will be blocked by the firewall then why this ips message appears on clients.

    which one is first line of defence  firewall or IPS



  • 2.  RE: which one blocks first sep firewall or sep IPS (need symantec tech. support's help)

    Posted May 15, 2009 12:56 PM


  • 3.  RE: which one blocks first sep firewall or sep IPS (need symantec tech. support's help)

    Posted May 15, 2009 01:39 PM
    Hi Sandip

                   Sorry but have you checked the links you provided They are no mare man.Can you give an updated link that works


  • 4.  RE: which one blocks first sep firewall or sep IPS (need symantec tech. support's help)

    Posted May 15, 2009 01:44 PM
    Hi,

           Sorry for that....

    Please check the links below which explain the feature and working of Firewall and IPS.

    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007121714495348       Firewall

    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008032011043948       IPS


  • 5.  RE: which one blocks first sep firewall or sep IPS (need symantec tech. support's help)

    Posted May 16, 2009 01:35 AM
    Still Confused

          which one blocks first firewall rule or IPS signature


  • 6.  RE: which one blocks first sep firewall or sep IPS (need symantec tech. support's help)
    Best Answer

    Posted May 16, 2009 05:43 AM
    It depends on the direction of the traffic.

    If the traffic is outbound from the client, it will hit the IPS engine first, then the firewall.  If its inbound to the client it will hit the firewall first, then IPS.

    hth



  • 7.  RE: which one blocks first sep firewall or sep IPS (need symantec tech. support's help)

    Posted May 16, 2009 08:19 AM
    Thanks paul
              If firewall is first for inbound then can you answer my post below
    https://www-secure.symantec.com/connect/forums/ntp-updated-firewall-rule-not-working-some-clients