Endpoint Protection Small Business Edition

 View Only
  • 1.  Allow or Block firewall rule not working

    Posted Sep 18, 2014 08:14 AM
      |   view attached

    Hi ,

     

    I had created a rule for Blocking all Websites and allow only Hotmail website.

    The rule is not working .

    i changed the rule as mention in the video in Symantec website but found no change.

    i have attached the rules which i export from the firewall poliy and attached the same.

    Kinldy guide me if any errors found.

    My Operating system is windows 7 Ultimate X64 bit.

    Regards

    :USK.

    Attachment(s)

    zip
    Allow and Block.zip   6 KB 1 version


  • 2.  RE: Allow or Block firewall rule not working

    Posted Sep 18, 2014 12:47 PM

    You only need to put *.hotmail.com for the host

    The host should also only be remote and set to ANY



  • 3.  RE: Allow or Block firewall rule not working

    Posted Sep 18, 2014 04:31 PM

    Correct on the local ports, those are not correct. Only remote should be 80/443 (unless you use a proxy).



  • 4.  RE: Allow or Block firewall rule not working
    Best Answer

    Posted Sep 19, 2014 04:36 AM

    First of all, enable traffic log in both rules to see what happens -- or not happens surprise

    In both rules, delete local ports 80/443 under Service. Your local port is unknown, the browser determines it randomly (it's a number above 1024).

    As Brian says, in the Allow rule only put *.hotmail.com for the host and delete the other stuff (but see below).

    In the Block rule delete the remote hosts ("Domain name: *"). Under "Service" you are already blocking the outgoing stuff for ports 80 and 443, that is sufficient.

    Put both rules in one Firewall policy, the allow rule above the block rule.

    However, even after these changes it probably won't work angry That's because a call of hotmail.com triggers calls of some other domains. And finally you will be redirected to live.com.

    In my tests, you have to put (at least!) these remote domains in the allow rule:

    *.hotmail.com
    *.gfx.ms
    *.verisign.com
    *.live.com

    To retrieve these domains (and for other things), the traffic log is very helpful (Client GUI > View Logs > Network Threat Protection > Traffic log).

    ###EDIT

    To get better results, just put a domain name (hotmail.com instead of *.hotmail.com etc.) in the domain list.

     

    HTH!



  • 5.  RE: Allow or Block firewall rule not working

    Posted Sep 21, 2014 02:13 AM

    Thank you for your immediate response Brain.

    I am able to Block all sites and allow Hotmail.

     



  • 6.  RE: Allow or Block firewall rule not working

    Posted Sep 21, 2014 02:15 AM

    Hi,

    Thank you for your support.

    your instructions were clear and with that i am able to allow Hotmail only.