SEP Firewall Performance Improvements with TCP Reset Action
We use Symantec Endpoint Protection with Network Threat Protection Managed Firewall to achieve PCI compliance. Before I dive into the issue essentially the setup is deny inbound AND outbound except those specific IP addresses and ports needed to perform business operations. One issue is that the cashier stations generally access a currency converter website (as an example) that has adds to other websites. Depending on the order that the page loads the site can (and usually does) take an extremely long time to fully load. This is because the SEP firewall just drops those ad connections (which it is suppose to), but meanwhile the application (in this case IE or firefox) waits for the connection to timeout. This can cause the page to take several minutes (I have seen up to 10 min) to load (including the tool that we want to use). Please add a feature in the Network Threat Protection Firewall actions menu that allows the client firewall to send a TCP Reset to the application. This will make it so the application no longer waits on blocked connections. I have removed all DNS resolution and have tracked this down to this very specific issue.
In summary:
Add a TCP Reset in the list along side the accept and drop actions. TCP reset will notify the application not to wait.