截屏视频帮助
Symantec to Separate Into Two Focused, Industry-Leading Technology Companies. Learn more.

SEP 11.0.7200.1147 NTP blocks outgoing http traffic

创建时间: 05 7 月 2012 | 12 条评论

Hi there,

a few weeks ago we installed the SEPM version 11.0 RU7 MP2 and updated round about 100 Vista and Windows 7 (64Bit) clients. After a successful testing phase (no incidents recognized) we updated nearly 1000 clients (mostly Windows 7 64 Bit) on a different Managementserver, which also was updated to 11.0 RU7 MP2.

Now, after a few weeks in prdouction we have only a few clients that have problems with the Symantec firewall (NTP). After a while the firewall modul starts blocking http traffic, https still working. Furthermore the firewall blocks only public IP adresses via http, I can still reach private adresses (i.e. my routera at home).

Any ideas where I can start my investigation in this bug (?) or did someone expected the sam issues ?

My second question : How can I downgrade these clients within the SEPM console ?

Kind regards

mmrayy

评论 条评论跳转至最新评论

Mithun Sanghavi 的图片

Hello,

In your case, I would suggest you to check the Traffic Logs on the SEP clients machines first and identify if these traffic are legitimate.

Are these Clients updated with Latest MS security patches, service packs, with latest vendor patches (like Adobe, etc).?

IPS signatures do block such traffic when they are exploiting vulnerabilities.

Hope that helps!!

Mithun Sanghavi
Senior Consultant
MIM | MCSA | MCTS | STS | SSE | SSE+ | ITIL v3

Don't forget to mark your thread as 'SOLVED' with the answer that best helped you.

Mohan Babu 的图片

http://www.symantec.com/docs/TECH102412

TSE debugging

Mohan Babu

moglie20@gmail.com

+91 9884382160

Your satisfaction is very important to us.If you find above information helpful or it has resolved your issue...please mark it accordingly :)

wroot 的图片

So, i'm not alone with this (https://www-secure.symantec.com/connect/forums/iss...) Do you know when exactly it has started happening for you? Because we also had testing group and it was fine for 2 weeks. So i have upgraded all our PCs to 11.0.7200.1147 on 07.04 and internet connection loss issues started right after this. But maybe it was only a coincidence and it is actually some definition change since 07.04.

mmrayy 的图片

.. of our SEPM to Version 11.0 RU7 MP2 and update of our clients. Before that everthing was good. In our environment we have location based policy profiles, when we leave one location where NTP is inactive and went to a location where the policy demands the NTP module it prevents access to HTTP.

I will upload some traffic logs by the end of this week, because I have no actual logs.

@Mohan Babu: I have generated some debug.logs

附件大小
debug.log_.txt 255.7 KB
wroot 的图片

Can you give a date when did you update your SEPM and clients? I want to rule out the definitions bug probability (if it started to behave like this before the July 4).

mmrayy 的图片

Sorry I have no clue when it starts exactly, but it starts definitely before the 4th of july.

regards

mmrayy 的图片

we tested the behavior with a complete emtpy firwall ruleset and without Intrusion Prevention and the error still appears.

wroot 的图片

I have created new group and disabled firewall policy for it, then i moved all clients to this group and this fixed the issue for the time being. I'm now downgrading to older version (yeah 200+ manually downgrading..). 12 version has issues with some software on our servers, so can't do upgrade on top either.

mmrayy 的图片

disabled firewall or removed the complete ruleset ?

same for ips ? removed or disabled ?

do you need to uninstall the "old" version before you can downgrade ?

cheers

wroot 的图片

Disabled firewall policy (you can enter the policy and uncheck it inside, then ir becomes pale in the list). Can't say for sure for IPS and i have already rebuild the server. Probably you can do the same just to be sure. Personally i don't see much use of it :)

Yes, you will have to uninstall 11.0.7200 version as 11.0.7101 won't install on top and will say that you already have newer version. You will have to restart after the uninstall and then restart after the 11.0.7101 install (to enable NTP module).

Pete Sutsos 的图片

We're experiencing the same problem here with NTP and SEP 11.0.7200.1147:  Internet traffic will stop however internal traffic will work.  I've seen users go for a few days, sometime only a few hours before the problem comes back.

  • All Windows 7 SP1 32 and 64 bit
  • Disabling NTP temporarily sovles the problem
  • Rebooting Windows temporarily solves the problem
  • Restarting the SEP service does not help
  • The NTP Traffic logs have stopped logging traffic before the problems occurs, sometimes hours before it occurs. 
  • Uninstalling, Cleanwiping, and re-installing the same SEP 11.0.7200.1147 does not help. 

The only solution has been to uninstall, reboot, and downgrade to 11.0.7 MP1.  11.0.7 MP1 had been rock solid, so was 11.0.6 MP3 (which solved that nasty 64bit SMB 2.0 problem). 

Luckily we're testing this and it's only deployed to 5 or so computers.

Looks like a 12.x migration is my future sooner than later.  Once 12.1.2 is Windows 2012/Windows 8 ready, time to leave this and move up. 

mmrayy 的图片

We are in a testing phase of 12.1.x Beta2 and will prepare an update of our Symantec structure as soon as the RU2 is available.

As I´ve heart from Symantec they will release the final version by the end of october 2012.

The Beta2 runs smoothly on our 2012 Servers and 8 Clients.

So raise your glasses ... cheers