Endpoint Protection

 View Only
  • 1.  Custom IPS signature website blocking

    Posted May 26, 2010 01:13 PM
    I am implementing the blocking of site using custom ips but the link below is not working for me.

    http://service1.symantec.com/support/ent-security.nsf/854fa02b4f5013678825731a007d06af/9c561a4628b3c9a44925747f007b19cd?OpenDocument

    I read through the forum and have done the following suggestions already:

    - there should space after comma
    - there should be existing main IPS policy in place

    Any ideas?
     


  • 2.  RE: Custom IPS signature website blocking

    Posted May 26, 2010 01:16 PM


    How to block/allow website access using the Symantec Endpoint Protection Manager custom Intrusion Prevention Signature policy


    http://service1.symantec.com/support/ent-security.nsf/854fa02b4f5013678825731a007d06af/9c561a4628b3c9a44925747f007b19cd?OpenDocument



    About custom IPS signatures

    http://seer.entsupport.symantec.com/docs/331103.htm


  • 3.  RE: Custom IPS signature website blocking

    Posted May 26, 2010 01:30 PM
    You can export your policy and upload to see if there is something we can see that is a problem


  • 4.  RE: Custom IPS signature website blocking

    Posted May 27, 2010 04:24 AM
      |   view attached
    Here you go, please see screenshot. I have also attached a zip file which is the exported policy I am testing.

    Let me know if there is anything else I need to provide.

    Attachment(s)

    zip
    Block Site.zip   1 KB 1 version


  • 5.  RE: Custom IPS signature website blocking

    Posted May 27, 2010 07:14 AM
    I finally got this working with this syntax:

    rule tcp, dest=(8080), msg="GOOGLE BLOCKED", content=www.google.com.ph 

    dest=(80) does not block the site for me.  Can someone explain why alt-http port works not http?

    Why dest=(443) does not work as well when accesing facebook?


  • 6.  RE: Custom IPS signature website blocking
    Best Answer

    Posted May 27, 2010 10:51 AM
    I have tested this policy on my machine and it works just fine and blocks all that is entered. Sounds like there might be database corruption. I would make a new group and assign the policy to the group then move the client to that new group. Also make sure you are not doing this while connected to the server in a RDP session unless you are using the mstsc -v:servername /admin and verify your user has ID 0 in the task manager users tab.




  • 7.  RE: Custom IPS signature website blocking

    Posted May 27, 2010 11:57 AM
    Thanks iofractal. Im good on this. Its the rdp console made it work now. =)

    We can close this thread.


  • 8.  RE: Custom IPS signature website blocking

    Posted May 27, 2010 12:18 PM
    Good I am glad I could assist you! 


    Remember to mark the solution!! 

    Thanks!