Got a fun one. After the ENS OCT update, SYSCORE caused some strange things. Now I am seeing the HIPS Firewall have an inbound connection and ID the application, IP/Port local and IP/Port remote, but then see another rule fire for the outbound traffic but without the Application. A bad thing when you are doing port white-listing via application, port and IP. On our new server, managed by the same ePO with the same modules and policy, I see the inbound traffic with application/ip/port as excepted/normal with no outbound traffic (as excepted/normal). Am I'm on the right track with thinking its a corrupt SYSCORE?
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.