How to configure Endpoint Protection client for use with Microsoft's DirectAccess

book

Article ID: 180567

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

 

Resolution

To configure Symantec Endpoint Protection (SEP) client for use with Microsoft DirectAccess (DA):

  1. Ensure the Windows Firewall service is enabled:
    1. Use the steps in the following document: https://support.microsoft.com/en-us/help/4028544/windows-turn-windows-firewall-on-or-off
      or
    2. Go to Control Panel > System and Security > Windows Firewall.
  2. If SEP is installed and the service is enabled you should see a notification that SEP is managing these settings:
  3. Once the Windows Firewall service is active, confirm that the "ConSecRuleRuleCategory" is managed by "Windows Firewall"
    1. Open a command prompt.
    2. Type the following:
      netsh advfirewall show global
    3. Scroll to the bottom and look for ConSecRuleCategory or ConSecRuleRuleCategory (varies based on the version of Windows).
    4. Confirm its value is Windows Firewall.
       

       
  4. Configure the SEP client firewall integration and allow IPv6 traffic on the Symantec Endpoint Protection Manager (SEPM) to allow DA to function.
    1. The SEP client can be configured to allow or disable the Windows Firewall in the Firewall Policy on SEPM.
      1. In SEPM, click Policies > Firewall.
      2. Edit the Firewall policy applied to clients using DA. The suggested configuration for use with Microsoft's DA is:
         

         

Note: If the SEP Firewall policy option No Action or Restore if Disabled is chosen, the Microsoft Firewall is in charge of all four categories and SEP Firewall rules are not applied. You can verify if SEP is managing the first three firewall configuration categories by the command `netsh advfirewall show global`. If it is, then SEP firewall rules are applied as expected. 

For more information, see: 

  1. Ensure that the SEP Firewall is configured to allow all IPv6 traffic.

    Note: In SEP 12.1.x, open the SEPM console, click Policies > Firewall, and change the SEP firewall rules for IPv6 traffic from Block to Allow.

    To create an Allow rule for IPv6:
    1. Log on to the Endpoint Protection Manager (SEPM).
    2. Click Policies > Firewall, highlight the policy you want to edit, and then click Edit the Policy.
    3. Click Rules > Add Rule.
    4. Enter a rule name, and then click Next
    5. Select Allow connections, and then click Next.
    6. Select All Applications, and then click Next.
    7. Select Any computer or site, and then click Next.
    8. Select Only the communications selected below.
    9. Click Add, and then do the following:
      1. Set the Protocol to Ethernet.
      2. For Protocol Type, add Ipv6 (0x86dd).
      3. Click OK.
    10. Click Next.
    11. Choose your desired log setting.
    12. Click Finish, and then click OK.
  2. After the policy propagates to the client computers, DirectAccess should now function as expected.

 

Attachments