Endpoint Protection

 View Only
Expand all | Collapse all

Blocking websites

SKP

SKPDec 14, 2011 04:05 AM

Migration User

Migration UserDec 14, 2011 04:49 AM

Migration User

Migration UserDec 14, 2011 06:29 AM

SKP

SKPDec 14, 2011 07:22 AM

SKP

SKPDec 14, 2011 08:08 AM

  • 1.  Blocking websites

    Posted Dec 13, 2011 06:38 AM

    Kinldy help me to block particular Website .I had followed the video provide by mudit kumar but it is not working.I had tested it on SEPM 12.1



  • 2.  RE: Blocking websites

    Posted Dec 13, 2011 06:56 AM

    Hello,

    Have a look at this! ;-)

    http://www.symantec.com/business/support/index?page=content&id=TECH92405&actp=search&viewlocale=en_US&searchid=1323777286693

    According to this, you should be able to create firewall rules to block the website.

     

    Regards,

    Marius



  • 3.  RE: Blocking websites

    Posted Dec 13, 2011 07:07 AM

    I had tried the same but not working



  • 4.  RE: Blocking websites

    Posted Dec 13, 2011 07:13 AM

    What does "not working" mean? Are the users able to access the site? Or do you get errors?



  • 5.  RE: Blocking websites

    Posted Dec 13, 2011 07:17 AM

    You may test blocking traffic to ALL websites by following this article:

    http://www.symantec.com/business/support/index?page=content&id=TECH95248&actp=search&viewlocale=en_US&searchid=1323777286693

    Let me know if that works!

     

    Regards,

    Marius



  • 6.  RE: Blocking websites

    Trusted Advisor
    Posted Dec 13, 2011 07:53 AM

    Hello,

    A Quick Note: It is important to have the Application and Device control and Firewall Installed on each Client machine. 

    Here are few Articles for the same:

    How to Restrict Users to Specific Web Sites by Creating Firewall Rules for Managed Clients
     
     
    How to block all website and allow only certain websites using Network Threat Protection Firewall rule.
     

     

    There are few Threads on the same issue as well, I would suggest a quick look into the same.

    https://www-secure.symantec.com/connect/forums/custom-ips-signature-website-blocking

    https://www-secure.symantec.com/connect/forums/how-block-access-specific-websites-both-url-and-ip-address

    https://www-secure.symantec.com/connect/forums/website-blocking-custom-ips-signatures

     

    Hope that helps!!



  • 7.  RE: Blocking websites

    Posted Dec 14, 2011 01:17 AM
      |   view attached

    User can able access the site .kinldy find the policy file attached below

    Attachment(s)

    zip
    Google Block.zip   11 KB 1 version


  • 8.  RE: Blocking websites

    Broadcom Employee
    Posted Dec 14, 2011 01:28 AM

    have you checked the polciy been taken by client? have you restarted the client?



  • 9.  RE: Blocking websites

    Posted Dec 14, 2011 03:43 AM

    Policy taken by client but not restarted



  • 10.  RE: Blocking websites

    Posted Dec 14, 2011 03:49 AM

    Restart your client and try again to access to website!



  • 11.  RE: Blocking websites

    Posted Dec 14, 2011 04:05 AM

    Restarted but same problem.



  • 12.  RE: Blocking websites

    Posted Dec 14, 2011 04:49 AM
      |   view attached

    Import, distribute, restart, try again!

    Attachment(s)

    zip
    Google Block_0.zip   174 B 1 version


  • 13.  RE: Blocking websites

    Posted Dec 14, 2011 06:25 AM

    Getting error while importing the dat file Error:Invalid import file



  • 14.  RE: Blocking websites

    Posted Dec 14, 2011 06:29 AM
      |   view attached

    my mistake! Try again with the new file...

    Attachment(s)

    zip
    Google Block_1.zip   11 KB 1 version


  • 15.  RE: Blocking websites

    Posted Dec 14, 2011 07:22 AM

    Sorry......... same result



  • 16.  RE: Blocking websites

    Posted Dec 14, 2011 07:56 AM
    • Change rule, enter DNS domain as: *.*google*.*
    • enable logging
    • distribute to client
    • flush DNS Cache of test machine
    • try again


  • 17.  RE: Blocking websites

    Posted Dec 14, 2011 08:08 AM

    Done the same but no result



  • 18.  RE: Blocking websites

    Posted Dec 14, 2011 08:17 AM

    Check traffic log of the affected machine.

    Attach it to this thread.



  • 19.  RE: Blocking websites

    Posted Dec 14, 2011 08:33 AM

    Firewall rules only work under certain conditions, and I've not had good luck with the domain blocking in SEP. For one thing, with the akaimi or whatever it's called, the IP addresses are shared. I tried to block ebay's addresses (there are a lot of them) and ended up Walmart and many other sites got blocked because of the server and address caching with the akaimi or whatever it's called.

    HOWEVER, the URL won't change - say there's malware that's on www.mymalware.com and folks get redirected to that or it's a link in email and you want to block it. So you find the IP, put it in the firewall and block it today. That works for this morning - but the malware folks know they've been found out and folks are blocking them so they move to a different server........ SAME URL, different server and IP. NOW your great firewall rule won't do anything.

    Enter Custom IPS signatures!

    Policies, Intrusion Prevention, Custom Intrusion prevention policies

    and here is a rule that blocks a phishing site:

    rule tcp, dest=(80), saddr=$LOCALHOST, msg="Amazon phishing site", content="bfgzdxbj.info"

    You can block specific or multiple or all ports, set specific source addresses, the content can contain a simple URL string, or be more complex as needed. They have some decent documents on creating custom IPS rules here somewhere - but I'm fighting a few fires here so don't have a lot of time to dig and post 'em sorry..........

     



  • 20.  RE: Blocking websites

    Posted Dec 14, 2011 08:48 AM

    Well, IPS is not my darling...but here are some of the links ShadowsPapa mentioned:

    Creating Custom IPS Signatures:

    http://www.symantec.com/docs/HOWTO18301

    About Custom IPS Signatures:

    http://www.symantec.com/docs/HOWTO18308

    Also have a look to this Connect-Thread:

    Block Web Sites

    https://www-secure.symantec.com/connect/forums/block-web-sites

    ;-)



  • 21.  RE: Blocking websites

    Posted Dec 19, 2011 04:33 AM

     

    1. Block particular site by Symantec Endpoint protection:
    2. Choose particular Group and select policies
    3. Uncheck Inherit Policies check box
    4. Click on Firewall Policies and click on "Creat Non Shared policies from copy"
    5. Select Rules opton which on Leftside
    6. And then click on Add Rule and Click on Next
    7. Select Accroding to the requirements
    8. Select Host to Block particular site or system or Ip address
    9. Select Accroding to the requirements
    10.For Example : Here I want to block Facebook site
    11.Select DNS domain
    12. Provide the site name as below and click on next
    13. For example Type *.facebook.com and Click on Finish
    14. Rule 0 is created
    15. Select rule 0 and right click in the action column and select Block / Allow as per the requirements:
    16. To block/allow particular Port , click on Services column
    17. To block/allow any application , Click on application coloumn
     
     


  • 22.  RE: Blocking websites

    Posted Dec 27, 2011 01:54 AM

    Follow the Link for website Blocking.

    http://www.symantec.com/business/support/index?page=content&id=TECH95248&locale=en_US 

     

    Thanks

     

    Regards,

    Anil

     



  • 23.  RE: Blocking websites

    Posted Apr 26, 2012 04:07 AM

    Followers of this thread may be interested in this new whitepaper:

    Scams and Spam to Avoid on Facebook

    http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/scams_and_spam_to_avoid_on_facebook.pdf

    Please do keep yourselves (and any FB fans on your office network!) informed and secure!