SEP / SES blocking DEWESoft Krypton device
search cancel

SEP / SES blocking DEWESoft Krypton device

book

Article ID: 279075

calendar_today

Updated On:

Products

Endpoint Security Complete Endpoint Protection

Issue/Introduction

You have a DEWESoft hardware that communicates through the computer Ethernet port and is sometimes blocked or slowed.

When you use the associated software, device is not being detected.

Environment

SEP / SES 14.x

DEWESoft EtherCAT device

Cause

DEWESoft device communicates over non‐IP protocol and uses Ethertype 0x88A4. 

Traffic does not match your Firewall allow rules and gets blocked by the default rule: "Block all other traffic and don't log".

Resolution

Create a firewall rule that matches the vendor requirements. The traffic log (logging can be enabled in the Firewall policy) from the client will look as follow:

1/30/2024 11:32:46 AM    15    Blocked    Ethernet        0.0.0.0    0    0.0.0.0    34980        Outgoing    1/30/2024 11:27:41 AM    1/30/2024 11:27:41 AM    1    No    Block all other traffic and don't log    FF-FF-FF-FF-FF-FF    03-01-01-01-01-01    Default    Admin_Name    Domain_Name

So Ethernet traffic with remote MAC address FF: FF: FF: FF: FF: FF and local MAC address 03:01:01:01:01:01 is required for the device to work properly.

To mitigate the issue, create a rule for:

  • Ethertype 0x88A4
  • Source: 03:01:01:01:01:01
  • Destination: FF: FF: FF: FF: FF: FF

If needed, adjust other conditions to your requirements to ensure the safety of the rule.