Endpoint Protection

 View Only
  • 1.  Possible record only blocked in traffic log?

    Posted Nov 13, 2017 05:17 PM

    We just switch to SEP's firewall and found the firewall's traffic log logs everythijng, both allowed and blocked, I can't find a way to disable the log or just record the blocked traffic. Is it possble to do that?



  • 2.  RE: Possible record only blocked in traffic log?

    Posted Nov 14, 2017 12:01 PM

    Just make sure the boxes are unchecked (or checked) for what you need in the rule:



  • 3.  RE: Possible record only blocked in traffic log?

    Posted Nov 14, 2017 01:41 PM

    Is this on the client side or? as I can't find that at the client's firewall rules setting page

    we are using SEP 14



  • 4.  RE: Possible record only blocked in traffic log?
    Best Answer

    Posted Nov 14, 2017 03:30 PM

    My screenshot is from the SEPM, not the SEP client.

    It sounds like you're running an unmanaged client. If so, there is no option to turn logging of rules off. When you create them, they're logged automatically, both block and allow actions.