search cancel

Endpoint Protection clients in mixed or client control mode block IGMP traffic when configured to allow.

book

Article ID: 175278

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

When using Client or Mixed Control mode, Endpoint Protection (SEP) clients will block IGMP network traffic with the "Allow IGMP traffic" user defined firewall rule. 

Firewall traffic logs show:

Timestamp         Severity               Action   Protocol               Remote Hostname          Remote IP           Remote Port      Local IP            Local Port            Application         Direction              Start Time           End Time             Count    Alert      Rule              

6/27/2019 3:42:39 PM   3              Blocked                IP                            172.12.255.100  0              224.0.0.22            2                              Incoming             6/27/2019 3:42:13 PM   6/27/2019 3:42:25 PM   5              No          Allow IGMP traffic          

Pic from UI:

Resolution

{KNOWN_ISSUE.EN_US}

As a workaround, you can edit the "Allow IGMP traffic" rule to block the traffic and then set it back to allow and the rule should work properly. 

Attachments