Endpoint Protection

 View Only
Expand all | Collapse all

How to allow mobile data card traffic in SEPM through firewall rules?

ℬrίαη

ℬrίαηDec 20, 2012 11:16 AM

Migration User

Migration UserDec 20, 2012 11:32 AM

  • 1.  How to allow mobile data card traffic in SEPM through firewall rules?

    Posted Dec 20, 2012 10:55 AM

    Hi,

    We have SEPM 11.0.5 running with over 10.000 clients. Some of these clients are running SEP 11.0.5, other 11.0.7 and other v12.1.

    Until recently, we have had not problem with any provider of mobile data cards in the world. The traffic being generated by them was not being blocked. But recently, some of our users in India have had problems with some newly purchased mobile 3G data cards, as their traffic is being blocked by SEP Network Threat Protection firewall component.

    The problem I have is that, in the firewall log, the ETHERNET header is always different (sometimes it's 0xAAe, others it´s 0xA0B, others it's 0xA82, etc). So I can't create a policy based on the Ethernet header.

    Can anyone suggest any other way of doing it?

     

     

    Thanks!



  • 2.  RE: How to allow mobile data card traffic in SEPM through firewall rules?

    Posted Dec 20, 2012 11:09 AM

    HI,

    check NTP logs.....and find out wich rule of firewall bloacking IT

    Did you received any error Msg ?

     



  • 3.  RE: How to allow mobile data card traffic in SEPM through firewall rules?

    Posted Dec 20, 2012 11:12 AM

    Hi Ashish,

    Yes, this is the first thing I did. The rule blocking the traffic is the general one: "Block all other traffic".



  • 4.  RE: How to allow mobile data card traffic in SEPM through firewall rules?

    Posted Dec 20, 2012 11:16 AM

    Is it trying to use a specific port?



  • 5.  RE: How to allow mobile data card traffic in SEPM through firewall rules?

    Posted Dec 20, 2012 11:24 AM

    Again, the port is also constantly changing: 2690, 2571, 2695, 19069, 41516, 49909, 52170, ...

    I must say that the most repeated one is 2571. Information on this port is not relevant, it can be used by malware, but also by protocol CECSVC.



  • 6.  RE: How to allow mobile data card traffic in SEPM through firewall rules?

    Posted Dec 20, 2012 11:26 AM

    Can you dump the log into excel and post here? Just a few lines should do it so we can see the exact coding.



  • 7.  RE: How to allow mobile data card traffic in SEPM through firewall rules?

    Posted Dec 20, 2012 11:32 AM
      |   view attached

    Sure, here it is. Just a few lines, as an example.

    Attachment(s)

    xlsx
    NTPLog.xlsx   10 KB 1 version


  • 8.  RE: How to allow mobile data card traffic in SEPM through firewall rules?

    Posted Dec 20, 2012 11:45 AM

    See what happens when you create a policy based on Ethernet but leave the protocol type blank



  • 9.  RE: How to allow mobile data card traffic in SEPM through firewall rules?

    Posted Dec 20, 2012 11:49 AM

    I will try that, but... is that advisable really? Won't that allow ALL ethernet traffic?



  • 10.  RE: How to allow mobile data card traffic in SEPM through firewall rules?

    Posted Dec 20, 2012 11:56 AM

    That would be up to you. Easiest way is create the Ethernet policy but it sounds like you have multiple people using these cards so that will be a nightmare.

    You could move these users into a custom group and apply the policy allowing this traffic only to them.



  • 11.  RE: How to allow mobile data card traffic in SEPM through firewall rules?

    Posted Dec 20, 2012 12:01 PM

    Yeah, that's what I figured I would do too. I have created the policy, but I won't be able to test it until tomorrow. Thanks for the help, I will tell you tomorrow how it goes.



  • 12.  RE: How to allow mobile data card traffic in SEPM through firewall rules?

    Posted Dec 20, 2012 11:57 PM

    Why don't you use application triggers in your firewall rules? As you have said, the ports a constantly changing, but I believe, that you have a limited number of applications that should be allowed to use these ports.

    You can read about the application triggers in SEP Admin guide (please, see page 472). Please, look at the following article too: http://www.symantec.com/business/support/index?page=content&id=HOWTO81237#v10221886

     



  • 13.  RE: How to allow mobile data card traffic in SEPM through firewall rules?

    Posted Jan 02, 2013 09:30 AM

    Hi,

    I tested that and it worked as a workaround. I created a specific group and move the machines that needed to use that 3g data card in there. This is just temporary until I can figure out exactly what policy works for this specific device.

    Thanks for your help Brian. Appreciated. I don't mark this as solved because this is just a workaround.

     



  • 14.  RE: How to allow mobile data card traffic in SEPM through firewall rules?

    Posted Jan 02, 2013 09:33 AM

    Thanks for the suggestion, but I don't think using application triggers for allowing traffic is really an option. I know about them and use them to block traffic from and to specific applications, but allowing traffic is too wide. I have no idea what these specific users will need to do (browse internet, ftp, whatever...).



  • 15.  RE: How to allow mobile data card traffic in SEPM through firewall rules?

    Posted Apr 24, 2013 02:17 AM

    For those following this thread:

    12.1 RU2 MP1 introduces the fix for this issue:

    New fixes and features in Symantec Endpoint Protection 12.1 Release Update 2 Maintenance Pack 1

    Article:TECH204685  |  Created: 2013-04-03  |  Updated: 2013-04-12  |  Article URL http://www.symantec.com/docs/TECH204685
     
    Systems are unable to connect to the network using 3G USB cards after installing Symantec Endpoint Protection firewall
    Fix ID: 2949361
    Symptom: Certain USB 3G cards require the configuration of extensive protocols to allow network traffic to pass through the firewall.
    Solution: Updated Teefer to allow for traffic missing certain header components to be processed.