Endpoint Protection

 View Only
  • 1.  traffic blocked from ntoskrnl.exe

    Posted Apr 16, 2012 08:31 PM

    Hi

    Internal intranet websites, Browsing fine, But as soon as we attempt to access websites external to org,


    Get SEP11 blocking traffic with this message: traffic blocked from ntoskrnl.exe

     

    Unsure of whats going on



  • 2.  RE: traffic blocked from ntoskrnl.exe

    Posted Apr 16, 2012 09:47 PM

    Hope this helps

     Ntoskrnl.exe--is the file used for file and print sharing..

    So all the computers in the network poll on the UDP port 137 ,138 to find computers near them.
    So even if you are not using the remote computer for file sharing you might get this pop-up.
    Since on Unmanaged computer the option for Browse File and Print sharing on the Network in unchecked ( turned off )
    So you might be getting this pop-up.
    So what you can do is 
    Open SEP Interface-Under Network Threat Protection -Options-Change Settings-Microsoft Windows Networking-All network Adapters--Check both the boxes below then one by select all the adapters and make sure both the boxes are checked for all you Network adapters in the drop-down..
     

    Checked this forums.

    https://www-secure.symantec.com/connect/forums/symantec-endpoint-protection-110420275-blocked-traffic-ntoskrnlexehelp

    https://www-secure.symantec.com/connect/forums/nt-kernel-amp-system-ntoskrnlexe-blocking-message-repeatedly-appearing

     



  • 3.  RE: traffic blocked from ntoskrnl.exe

    Posted Apr 17, 2012 06:37 AM

    Hi,

    Un-check Display Intrusion Prevention Notifications and check whether that file is using any infected process.

    Thanks



  • 4.  RE: traffic blocked from ntoskrnl.exe

    Posted Apr 17, 2012 11:26 PM