Endpoint Protection

 View Only
  • 1.  Traffic has been blocked from this application svchost.exe

    Posted Feb 19, 2013 11:18 AM

    Hi There,

    We have recently installed SEPM  server SEP 12.1.2 and upgraded all the user computers using the Install package created from SEPM manager.

    Most of the time randomly all the clients are getting a notification message "Traffic has been blocked from this application: (svchost.edvoxe)".

    Can somebody please advise and give some solution to solve this problem. It will be very helpfull and highly appreaciated.

    Thanks,

    Cenil.



  • 2.  RE: Traffic has been blocked from this application svchost.exe

    Posted Feb 19, 2013 11:21 AM

    This is likely caused by the firewall.

    If you look at the Traffic log on an affected client, what does it show? and what is the rule being blocked?

    Can you attach the traffic log of an affected client?

    Check this:

    https://www.symantec.com/business/support/index?page=content&id=TECH165942



  • 3.  RE: Traffic has been blocked from this application svchost.exe

    Posted Feb 19, 2013 11:41 AM

    hi,

    try this

    Is the Notification comming on Vista or Windows 7 machines? If yes, follow the steps below:

    1. Turn off the iphelper service, set to manual. This stops the warning dialog from popping up.

    2. Open the Network and Sharing Center, click "Change adapter settings", select the adapter being used, right-click and select "Properties".
    Uncheck the box next to "Internet Protocol Version 6 (TCP/IPv6)".
    IPv6 is on by default in Vista/Win7.

    3. Restart machine.

    Check this thread

    https://www-secure.symantec.com/connect/forums/constant-notification-traffic-has-been-blocked-application-svchostexe



  • 4.  RE: Traffic has been blocked from this application svchost.exe

    Posted Feb 19, 2013 11:53 AM

    Most likely it is being caused by the default firewall rule to block the IPv6 traffic - if you don't use IPv6 you can turn it off from you network adapter settings (right click -> properties -> deselect IPv6)  or you can simply turn of the logging for this firewall rule from SEPM firewall policy.