Endpoint Protection

 View Only
  • 1.  Blocking IP address for 600 seconds

    Posted Nov 30, 2016 11:09 AM

    I have a VLAN set up for a Ubiquiti camera system.  The recorder keeps getting its IP address blocked.  I have added a firewall rule to allow all incoming and outgoing connections on the entire VLAN subnet but it is still being blocked.  Is there another way for SEP to allow all traffic on that subnet into and out of my network?



  • 2.  RE: Blocking IP address for 600 seconds

    Posted Nov 30, 2016 11:12 AM

    Have you tried allowing it to/from this specific host only?

    https://www.symantec.com/connect/forums/endpoint-blocking-traffic-local-appliance

    If you check the clients Security log, does it show this as a Denial of Service?



  • 3.  RE: Blocking IP address for 600 seconds

    Posted Nov 30, 2016 11:19 AM

    in the unmatched traffic setting of the client/client grouop try to toggle it between

    Allow IP traffic or Allow only application traffic.

     

    ip traffic.JPG



  • 4.  RE: Blocking IP address for 600 seconds

    Posted Nov 30, 2016 11:51 AM

    Yes it shows as blocked.  I have added a firewall rule to allow all traffic from the specific subnet, allow all UDP traffic, and I allowed all traffic from the host and its still getting blocked as a port scan.  Its being blocked under the default rule of "block all other IP traffic".



  • 5.  RE: Blocking IP address for 600 seconds

    Posted Nov 30, 2016 11:54 AM
    Is this rule at the top of the stack?


  • 6.  RE: Blocking IP address for 600 seconds

    Posted Dec 01, 2016 01:31 AM

    HI,

     

    Please add that IP addres to IPS exclude host.

     

    IPS.JPG