Hi,
I am interested in locking down the McAfee ENS firewall so that only the EPO server and the management workstation can connect to the agent on each PC.
When I look at the firewall rules (I just edited the default policy to customize it) I don't see a rule that allows EVERY IP ADDRESS to connect to port 8081 TCP.
Does anyone know which rule does this? I just want to modify it so that only source IPs that need to connect to it can connect to it.
I just want to note that we have the agent setup to accept connections ONLY from the EPO server but we don't want port 8081 showing as open during port scanning.
Hi @enxl,
Thank you for your post.
This allowing of communication for McAfee applications are carried out by the McAfee Core networking rules. While they are not dependent on the ports and protocols in general, it is important that there is no "Customization" allowed to these core networking rules, however, you can duplicate and try to recreate these rules as needed.
Allow McAfee signed applications | Allows inbound and outbound network traffic related to McAfee products based on signer certificate value. | No |
Allow McAfee signed applications 2 | ||
Allow McAfee signed applications 3 | ||
Allow McAfee signed applications 4 |
Please note that not all rules from core networking rules can be duplicated as mentioned in this KBA:
https://kc.mcafee.com/corporate/index?page=content&id=KB92563
I sincerely hope this helps.
That is tremendously sloppy, I keep running into decisions your company makes that make your customers' environments less secure. Please fix it so that the rule in question is "broken out" from the other core networking rules.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA