Endpoint Protection Client fails to detect a Port Scan
Article ID: 164901
A Symantec Endpoint Protection (SEP) Client does not detect Port Scan tests.
A Firewall Rule exists that allows traffic from the computer that executes the Port Scan.
SEP only detects a port scan for blocked traffic. To allow port scans to be detected as expected:
- Identify the Firewall Rule that allows the intended port scan traffic
- Disable or remove that Firewall Rule that allows the intended port scan traffic