Symantec Endpoint Protection giving alerts suddenly

Status
Not open for further replies.

Scot Busby

Customer
Joined
Jun 8, 2017
Messages
87
Reaction score
19
NOTE: I posted the below a few days ago and a forum user suggested I check the exclusions on the Symantec AV settings. I did that, added the exclusions back in, however, I am still receiving an increasing number of alerts from Symantec like the one below. The last post was closed as solved, so my only choice was to open a new thread. So at this point, there are exclusions in Symantec for the folders listed by 3CX, but still the alerts continue. Thank you for any thoughts anyone might have.

Hello,

We have Symantec Endpoint protection running on our phone system. We have been running this on our system since we started with the 3CX system several years ago and have not had any issues.

Over the past few days, I have received a few alerts with the below details. Any thoughts on this? I have received about 4 of these emails and each has a different port. The first one I received was for port 5001. The remaining attempts were 57000+ ports. Has anyone else experienced this?

IPS Alert Name
Attack: an intrusion attempt was blocked.

Status
Blocked

Attack Signature
Web Attack: Passwd File Download Attempt

Targeted Application
C:\PROGRAM FILES\3CX PHONE SYSTEM\BIN\NGINX\NGINX.EXE

Attacking IP
127.0.0.1

Targeted IP
127.0.0.1

Targeted Port Number
63418

Targeted Host Name
N/A
 
Hi Scot,

We do not recommend running any other software on your PBX beyond 3CX but if you must run antivirus we recommend excluding the following folders:

https://www.3cx.com/docs/manual/phone-system-installation-windows/#h.8fvtvgaubv22

A lot of the internal functions that the PBX does are not considered normal traffic for an endpoint, so it's understandable that the antivirus is considering it suspicious. You can expect to see more warnings if your antivirus is already treating internal PBX ports as a threat.
 
Hi @JohnS_3CX

Thanks for your reply. I had posted this before and someone posted the same thing, so I went to check the exclusions and they were missing, so I re-added them. I still get various alerts from the AV client even after adding those exclusions thought.

I understand things like this happen with unusual traffic and don't want to get too excited about these alerts, however, the suddenness by which they started bothered me a little. I've been running this phone system for several years now in this exact configuration (along with the AV client) and all of a sudden, I start to get these alerts. The AV client receives updates as well as 3CX, so that might just be the end result, however, I wanted to ask smarter people than me to ensure I'm not missing anything.
 
I think you should be ok, just be aware that the PBX will have traffic to/from 127.0.0.1 and this is indeed expected behavior.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,990
Messages
590,164
Members
164,927
Latest member
tohoken1