Endpoint Security Firewall rule needs to have tomcat9.exe in the allowed list for all communication related to Tomcat
Last Modified: 2022-12-02 12:00:56 Etc/GMT
Affected Products
Languages:
This article is available in the following languages:
Trellix CEO, Bryan Palma, explains the critical need for security that’s always learning.
As per Gartner, "XDR is an emerging technology that can offer improved threat prevention, detection and response."
Trellix announced the establishment of the Trellix Advanced Research Center to advance global threat intelligence.
Trellix Advanced Research Center analyzes threat data on ransomware, nation-states, sectors, vectors, LotL, MITRE ATT&CK techniques, and emails.
As of May 14, 2024, Knowledge Base (KB) articles will only be published and updated in our new Trellix Thrive Knowledge space.
Log in to the Thrive Portal using your OKTA credentials and start searching the new space. Legacy KB IDs are indexed and you will be able to find them easily just by typing the legacy KB ID.
Endpoint Security Firewall rule needs to have tomcat9.exe in the allowed list for all communication related to Tomcat
Technical Articles ID:
KB96212
Last Modified: 2022-12-02 12:00:56 Etc/GMT Environment
ePolicy Orchestrator (ePO) 5.10 Update 15 and later Endpoint Security Firewall (ENSFW) 10.7.x, 10.6.x Summary
NOTE: This issue occurs only if ePO server is installed with ENSFW on your computer. But, if the ePO server isn't installed with ENSFW, this article isn't relevant. In the ENSFW rule under ePO server, you have two specific rules to allow Outgoing and Incoming traffic from Tomcat. You see that in both the rules, ProblemPost upgrade to ePO Update 15, the Tomcat service isn't allowed through a remote connection. You see entries similar to the following in the
IP Address: Remote machine IP (From where you are accessing the EPO console) Description: APACHE COMMONS DAEMON SERVICE RUNNER Path: C:\Program Files (x86)\McAfee\ePolicy Orchestrator\Server\bin\tomcat9.exe Message: Blocked Incoming TCP - Source Remote machine IP : (remote port) Destination EPO server IP : (8443 (That is default and may differ if changed)) Matched Rule: Block all traffic Cause
The application SolutionTechnical Support is investigating this issue. As a temporary measure, implement the following workaround.
Workaround
Perform the steps below to resolve the issue:
Affected ProductsLanguages:This article is available in the following languages: |
|