Related Options in ePO:
ePO Policy > Endpoint Security Firewall: Firewall
☐ Treat match as intrusion
☐ Log matching traffic
ePO Server Settings > Event Filtering
☑ 35000: Traffic allowed by Firewall (Info)
☑ 35001: Firewall intrusion detected and handled (Info
Questions I've asked support about, multiple times, and I cannot seem to get a clear or consistent answer:
Solved! Go to Solution.
Hi @securitasis, from my testing with ENSFW 10.6.1 July Update:
Questions I've asked support about, multiple times, and I cannot seem to get a clear or consistent answer:
35000 event_name_35000=Traffic allowed by Firewall
event_desc_35000=Traffic allowed by FirewallFirewall 35001 event_name_35001=Firewall intrusion detected and handled
event_desc_35001=Firewall intrusion detected and handledFirewall 35002 event_name_35002=Traffic blocked by Firewall
event_desc_35002=Traffic blocked by FirewallFirewall 35003 event_name_35003=Firewall added adaptive rule
event_desc_35003=Firewall added adaptive ruleFirewall 35009 event_name_35009=Firewall is disabled from Mctray
event_desc_35009=Firewall is disabled from MctrayFirewall 35010 event_name_35010=Firewall timed groups are enabled from McTray
event_desc_35010=Firewall timed groups are enabled from McTrayFirewall 35011 event_name_35011=Firewall policy was corrupt and has been repaired
event_desc_35011=Firewall policy was corrupt and has been repairedFirewall 35012 event_name_35012=Firewall policy has been replaced with a new copy
event_desc_35012=Firewall policy has been replaced with a new copyFirewall
Also, if you would like to request changes to how ENS Firewall logging works, please submit a PER for review; ref KB60021.
You can find this info in the product guide:
• Treat match as intrusion — Treats traffic that matches the McAfee GTI block threshold setting as an
intrusion and displays an alert.
• Log matching traffic — Treats traffic that matches the McAfee GTI block threshold setting as a detection
and displays an event in the Event Log on the Endpoint Security Client. Firewall also sends an event to
McAfee ePO.
Hi @securitasis, from my testing with ENSFW 10.6.1 July Update:
Questions I've asked support about, multiple times, and I cannot seem to get a clear or consistent answer:
35000 event_name_35000=Traffic allowed by Firewall
event_desc_35000=Traffic allowed by FirewallFirewall 35001 event_name_35001=Firewall intrusion detected and handled
event_desc_35001=Firewall intrusion detected and handledFirewall 35002 event_name_35002=Traffic blocked by Firewall
event_desc_35002=Traffic blocked by FirewallFirewall 35003 event_name_35003=Firewall added adaptive rule
event_desc_35003=Firewall added adaptive ruleFirewall 35009 event_name_35009=Firewall is disabled from Mctray
event_desc_35009=Firewall is disabled from MctrayFirewall 35010 event_name_35010=Firewall timed groups are enabled from McTray
event_desc_35010=Firewall timed groups are enabled from McTrayFirewall 35011 event_name_35011=Firewall policy was corrupt and has been repaired
event_desc_35011=Firewall policy was corrupt and has been repairedFirewall 35012 event_name_35012=Firewall policy has been replaced with a new copy
event_desc_35012=Firewall policy has been replaced with a new copyFirewall
Also, if you would like to request changes to how ENS Firewall logging works, please submit a PER for review; ref KB60021.
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership: