04-07-2014 05:54 AM
We recently noticed in the firewall logs, that lots of our servers are trying to make a connection to the internet.
Now after futher inspection we found out it was "beserver.exe" proces that was causing the traffic.
This proces was used for threatcon polling, wich is weird because we where convinced that we turned it off.
Even edited the registry values to make sure that the constant polling would stop. But still no result.
Is there a different workaround for this problem or an other solution because i've hit a dead end so to seem.
Solved! Go to Solution.
04-07-2014 06:06 AM
Hi,
Have you followed the TN below?
http://www.symantec.com/docs/TECH154899
Otherwise have you tried to block those ports on the firewall to prevent traffic leaving your organisation?
Thanks!
04-07-2014 06:06 AM
Hi,
Have you followed the TN below?
http://www.symantec.com/docs/TECH154899
Otherwise have you tried to block those ports on the firewall to prevent traffic leaving your organisation?
Thanks!
04-07-2014 06:15 AM
Hi,
We only changed the registry, the hotfix we didn't install yet.
But the weird thing is before we did anything to fix it, some of our server tried to poll but others didn't.
And for the firewall, yes we blocked port 80 on all of our servers. But I am student doing an intership and it is my job to clean the firewall. So basically all traffic that is not harmfull or causing a threat to internal network must be resolved.
So I am going to suggest the hotfix to my boss, and if that fixes the problem I will let you know.
Anyways, thank for the fast reply.
04-15-2014 11:24 AM
Hey,
We installed the hotfix, it worked on all the server except for 2.
But those are backup servers but thats not really an issue anymore.
Thanks for the help.
04-15-2014 11:50 AM
Great, glad to have helped!
Thanks!