Endpoint Protection

 View Only
  • 1.  Blocking all P2P in SEP

    Posted Sep 09, 2014 09:32 AM

    Hi,

    I need to block p2p apps from running in my organization.

    http://www.symantec.com/business/support/index?page=content&id=TECH122597

    This KB article shows that SEP's built in IPS signatures can be used to block p2p traffic.

    My question is, will using this block most p2p software?

    I do not want to use the 'Application & Device Control' feature or SEP firewall configuration as they require manually updateing the p2p application executables list or their hash list.

    Thanks,

    Shuhood



  • 2.  RE: Blocking all P2P in SEP

    Posted Sep 09, 2014 09:34 AM

    See this

    What do P2P Applications do and How to block Peer to Peer Applications (P2P) using Symantec Endpoint Protection?

    https://www-secure.symantec.com/connect/articles/what-do-p2p-applications-do-and-how-block-peer-peer-applications-p2p-using-symantec-endpoin



  • 3.  RE: Blocking all P2P in SEP

    Posted Sep 09, 2014 09:50 AM

    Thanks James for the additional info, but I couldn't find an answer to the question.

    Does using built-in IPS signatures block most p2p?



  • 4.  RE: Blocking all P2P in SEP

    Posted Sep 09, 2014 06:28 PM

    These are the signature for which P2P apps it can detect:

    Capture_26.JPG

     

    By default they are not blocked and in some cases not even logged. You can add exxceptions as needed though to block and/or log.

    But alot of P2P apps are still missing from this list.



  • 5.  RE: Blocking all P2P in SEP

    Posted Sep 10, 2014 01:28 AM

    Thanks Brian.

    So it means, If I block p2p apps using built-in IPS p2p signatures, clients will still be able to run softwares like Utorrent which are not present in the list? (ofcourse considering I do not add other clients manually).



  • 6.  RE: Blocking all P2P in SEP

    Posted Sep 10, 2014 08:13 AM

    Don't get confused. IPS won't stop applications from executing. IPS only looks at network traffic and blocks accordingly. It doesn't stop s apps from running though.