Endpoint Protection

 View Only
  • 1.  I need to block specific IP addresses in SEPM

    Posted Dec 09, 2016 03:59 PM

    Hello everyone! I need to block about 200+ IP addresses in Symantec Enpoint Protection Manager.  The rules have been added already to our unmanaged clients manually.  We have about 40 PCs on our network.  We just purchased SEPM and wanted to export the firewall rules from one client to the SEPM. Unfortunately, it will only export the policy as .XML or .SAR.  SEPM only accepts .DAT.  So I figured I can just create the 5 firewall rules on the client to the manager, but when I go to Policy, Firewall Rules, Add a blank rule, and go to add......I can only choose 1 single IP address or a range of IP addresses.  The problem is....these 200+ IP addresses are from different subnets, etc.  I cannot do this by blocking a range!  In Symantec Endpoint Protection clients, you can just copy and paste the addresses divided by commas and add multiple different IPs in the firewall rule.  But you cannot in the manager.  



  • 2.  RE: I need to block specific IP addresses in SEPM

    Posted Dec 09, 2016 04:02 PM

    Yep, this will be manual entry. There is no option to import a comma delimted file into the host group section.



  • 3.  RE: I need to block specific IP addresses in SEPM

    Posted Dec 12, 2016 08:42 AM

    I don't understand why you can do it in the clients, but not in the manager.  Why would Symantec do that?  There has to be an easier way to add IP addresses in the firewall rules than to add them one by one.  This would take forever to do!