Hello,
Can you instruct me how to enable logging for Firewall component on ePO? When I viewed Firewall events report on the ePO, the content was empty. Whereas, the logging function of other components of ENS are fine.
Thank you.
Solved! Go to Solution.
Hello @sanba06c
Thanks for your post.
Please refer the below screenshot:
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Hello @sanba06c
Thanks for your post.
Please refer the below screenshot:
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
@vivs, Thank you for the useful solution! Btw, What kind of events should I choose if I just want to log only blocked events? For example, "Critical" and "Alert" only?
Hello @sanba06c
Thanks for your response.
afaik, It should be "Critical" and "Alert" only.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
@vivs, I still find the "Endpoint Security Firewall: Traffic block events" report empty.
Hi @sanba06c Did you see my earlier response? Ref https://community.mcafee.com/t5/Endpoint-Security-ENS/How-to-turn-on-logging-mode-for-Firewall-on-eP...
Do you have any custom Firewall rules created that have the "Log matching traffic" option set? If that is enabled, and that firewall rule is triggered on the client, it will generate an Event ID 35000 (Allow) or 35002 (Block) back to the ePO server (depending on what action you chose in the rule). Those events should be seen in the default Firewall queries; if not check the Threat Events for that specific Agent node within its properties.
@ktankink, I had read through your previous comment, but not paid careful attention to that. Now, I can see that option to enable firewall logging. However, in my case, the rule is like "deny all" other than customized one. I can read the log by viewing the client log directly, but this way seems inconvenient.
Hi @sanba06c The ENS Firewall does not log all blocked network traffic by default. Doing so requires that you enable the "Log matching traffic" or "Treat as intrusion" option inside the firewall rules you create, however, be aware that too much 'generic' logging of BLOCKED or ALLOWED network traffic can cause issues. Please reference the KB below.
KB90177 - Enabling the 'Treat match as intrusion' or 'Log matching traffic' logging options might cause high CPU use
https://kc.mcafee.com/corporate/index?page=content&id=KB90177
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA