cancel
Showing results for 
Search instead for 
Did you mean: 
julienf
Level 7
Report Inappropriate Content
Message 1 of 11

ePo 4.5 try to scan port on servers.

Hi all,

My network team just sent me a report which shows that the EPO server tries to connect to some ports (1200 to 5000 see ePo.xls) on many servers.


I would like to disable this scan but after research and many configuration changes i didn't find anything.

Can someone help me ?

Thanks.

Regards,

Julien.

10 Replies

Re: ePo 4.5 try to scan port on servers.

I am not sure how the traffic will look, but do you possibly have OS Fingerprinting turned on for Rogue System Detection?

julienf
Level 7
Report Inappropriate Content
Message 3 of 11

Re: ePo 4.5 try to scan port on servers.

Hi greatscott,

Thanks for your quickly feedback.

In attachment you can see my policy for rogue system detection.

ePolicy Orchestrator 4.5.0 (Build 937) - Mozilla Firefox.jpg

Re: ePo 4.5 try to scan port on servers.

Yes, I would uncheck the "Scan detected systems for OS Details" box, and then get with your network team to see if the traffic is persisting.

Note also that this may change Rogue System Detection for your environment. I am assuming it will just no longer pull OS Data, so rogues may show up with none of that.

julienf
Level 7
Report Inappropriate Content
Message 5 of 11

Re: ePo 4.5 try to scan port on servers.

It's done.

I need to restart something or it's automatic ?

i will check with my network team.

Re: ePo 4.5 try to scan port on servers.

Make the change, save the policy, then run a wakeup call on the system hosting your RSD agent (s). Should be all you need.

julienf
Level 7
Report Inappropriate Content
Message 7 of 11

Re: ePo 4.5 try to scan port on servers.

Hi Greatscott,

I have make a wakeup call on all my servers but after a check with my network team, nothing change

regards,

Julien

Re: ePo 4.5 try to scan port on servers.

Possibly disable RSD completely to test, I would also run a netstat and see what those connections are...

Message was edited by: greatscott on 8/28/12 6:58:53 AM CDT
julienf
Level 7
Report Inappropriate Content
Message 9 of 11

Re: ePo 4.5 try to scan port on servers.

I will try this and give you a feedback ASAP.

Re: ePo 4.5 try to scan port on servers.

I Greatscott.

I Just have a feedback from my network team and nothing change.