Endpoint Protection clients in mixed or client control mode block IGMP traffic when configured to allow.
search cancel

Endpoint Protection clients in mixed or client control mode block IGMP traffic when configured to allow.

book

Article ID: 175278

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

When using Client or Mixed Control mode, Endpoint Protection (SEP) clients will block IGMP network traffic with the "Allow IGMP traffic" user defined firewall rule. 

Firewall traffic logs show:

Timestamp         Severity               Action   Protocol               Remote Hostname          Remote IP           Remote Port      Local IP            Local Port            Application         Direction              Start Time           End Time             Count    Alert      Rule              

6/27/2019 3:42:39 PM   3              Blocked                IP                            172.12.255.100  0              224.0.0.22            2                              Incoming             6/27/2019 3:42:13 PM   6/27/2019 3:42:25 PM   5              No          Allow IGMP traffic          

Pic from UI:

Resolution

{KNOWN_ISSUE.EN_US}

As a workaround, you can edit the "Allow IGMP traffic" rule to block the traffic and then set it back to allow and the rule should work properly. 

Attachments