Endpoint Protection

Expand all | Collapse all

ETHERNET [type=0x806]

ℬrίαη

ℬrίαηAug 15, 2011 10:24 AM

Benjamin John

Benjamin JohnAug 15, 2011 03:03 PM

  • 1.  ETHERNET [type=0x806]

    Posted Aug 15, 2011 09:40 AM

    After upgrading to SEP 12.1, I'm getting a lot of ETHERNET [type=0x806] entries being logged in my firewall logs.

    I even tried creating a new FW rule that said allow these ethernet entries and don't log them, but they are still being created.

    (Verified that the new FW policy is in effect on the clients)

    This is being logged by the "Block all other traffic" rule.

    Anyone else seeing this?

    Thanks

     

    EDIT: "Enable anti-MAC spoofing" is not enabled.aa



  • 2.  RE: ETHERNET [type=0x806]

    Posted Aug 15, 2011 10:24 AM

    What log, traffic or packet?



  • 3.  RE: ETHERNET [type=0x806]

    Posted Aug 15, 2011 10:41 AM

    Traffic.

    It's mostly from the router/gateway. Occassionally from other machines on the LAN too.



  • 4.  RE: ETHERNET [type=0x806]

    Posted Aug 15, 2011 01:24 PM

    Block all other traffic is the last rule, so its not getting applied

    can u try creating this frm the user interface of the client?



  • 5.  RE: ETHERNET [type=0x806]

    Posted Aug 15, 2011 02:22 PM

    It sounds like it is getting applied?

    If I look in my logs, I see the rule being and applied (and blocking) although I'm not seeing the specific message mentioned in this post.



  • 6.  RE: ETHERNET [type=0x806]

    Posted Aug 15, 2011 02:49 PM

    How can you verify that a rule is being specifially applied? Other than comparing policy serial numbers, is there a way to see if a specific rule is being applied?

     

    0x806 is ARP traffic.

     

    I can verify that these entries were not being logged in SEP 11. In fact I have machines still on SEP11 (12 and 11 have the same policy).



  • 7.  RE: ETHERNET [type=0x806]

    Posted Aug 15, 2011 03:03 PM



  • 8.  RE: ETHERNET [type=0x806]

    Posted Aug 15, 2011 03:15 PM

    I'm just going by the "Action" column, which in my logs says "Blocked" so that is my assumption.



  • 9.  RE: ETHERNET [type=0x806]

    Posted Aug 15, 2011 03:16 PM

    I ment to say that blocked all rule is the last rule in the rule list, so if you have already applied a policy to allow ethernet traffic, its not working, coz the last rule is still blocking it.



  • 10.  RE: ETHERNET [type=0x806]

    Posted Aug 15, 2011 03:27 PM

    But would the log still show the Action as Blocked?

    It would make sense that if the allow rule was already applied than this rule should never be triggered, therefore not shown in the logs.



  • 11.  RE: ETHERNET [type=0x806]

    Posted Aug 15, 2011 03:27 PM

    Like I said earlier, I created a rule just to allow ARP entries so the FW log won't get so full. It doesn't seem to help, or is not being applied.

     

    I can't be the only one seeing this? or is there something unique about my network ???

     



  • 12.  RE: ETHERNET [type=0x806]

    Posted Aug 15, 2011 03:29 PM

    I'm not seeing that specific traffic but seeing other traffic that I'm questioning.

    That rule looks fine so I don't know why it is showing up in your log.



  • 13.  RE: ETHERNET [type=0x806]
    Best Answer

    Posted Aug 18, 2011 04:30 PM

    I was using the existing FW policies from SEPM 11,  Had to create a new policy to get rid of this.



  • 14.  RE: ETHERNET [type=0x806]

    Posted Sep 09, 2011 04:38 AM

    I have the same problem with the 0x806 log.

    I just created a rules at 1st position, allowing the traffic on 0x806 ethernet, with Source "Local network" and Destination "Local network", but it does not help. I tried with IP range, but it does not help also. But in the log, the local and remote is my local network.

     

    the only way to make it works, is to allow the trafic on any local, remote.... but I think this is not so secure...

     

    Any idea ?



  • 15.  RE: ETHERNET [type=0x806]

    Posted Sep 09, 2011 05:50 AM

    Hi,

     

    Just saw this behavior yesterday, iwas testing sep 11.x rules to sep 12.1...

     

    You don't have to recreate rules in 12.1 "style".

     

    In fact, in 12.1 "default" policy, look at the 2 last rules in the policy :

    BLOCK ALL IP TRAFFIC : LOG (the IP Protocol is matching ...)

    BLOCK ALL OTHER TRAFFIC : NO LOG

     

    In 11.x you don't have these 2 rules that log IP traffic which is blocked, and then block but don't log other trafic (like ethernet) ; you only have 1 rule like your screen shot, block all trafic and log.

     

    It explains why you were seeing these entries...

     

    So migrate your 11.x rules and modify the last 2 rules in that way...

     

    EDIT : don't add IP/network range matching in your rules since ARP is using Ethernet MAC adress... and select "all interfaces" ; the same is happening when filtering Multicast address, "ethernet adapter" only would not work...

     

    Cheers !

     

    LL