<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Noise Rule in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Noise-Rule/m-p/65137#M1663</link>
    <description>&lt;P&gt;We are running Endpoint in the cloud EPMAS (Endpoint Management As A Service).&amp;nbsp; To create Endpoint Firewall rules for the Endpoint client I use SmartEndpoint.&lt;/P&gt;&lt;P&gt;There is no destination field in the Endpoint client Firewall as the destination will always be the workstation/laptop&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 831px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2760iACC23A673927209F/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 842px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2761iA5B4FB4BD143A4E1/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thus the reason for using ports/services.&amp;nbsp;&lt;/P&gt;&lt;P&gt;239.255.255.250 is Simple Service Discovery Protocol (SSDP) port 1900 udp&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Wed, 16 Oct 2019 18:37:20 GMT</pubDate>
    <dc:creator>John_Gallagher</dc:creator>
    <dc:date>2019-10-16T18:37:20Z</dc:date>
    <item>
      <title>Noise Rule</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Noise-Rule/m-p/65048#M1658</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are the running Endpoint Client with the Firewall blade enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I go to Log Viewer, 99% of the logs is dropped multicast traffic from the Firewall blade.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.jpg.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2750i5E72954E0E98C2BE/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.jpg.png" alt="1.jpg.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This makes investigating the logs somewhat difficult as there are limited filtering options available.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most of the multicast traffic is LLMNR port 5355 tcp and SSDP port 1900 udp.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to create a Noise Rule (i.e. Track to None) so this traffic does not appear in the logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it ok to create a block rule only on the ports as below?&amp;nbsp; Note the source is Any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 842px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2751i039773CAE0A5FF2E/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can these ports be used by other services? And if they can then how would I create a Noisey Traffic Rule &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 02:16:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Noise-Rule/m-p/65048#M1658</guid>
      <dc:creator>John_Gallagher</dc:creator>
      <dc:date>2019-10-16T02:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: Noise Rule</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Noise-Rule/m-p/65061#M1659</link>
      <description>&lt;P&gt;First: What about the destination 239.255.255.250 ?&lt;/P&gt;
&lt;P&gt;Second: You show us an endpoint security client log, but create a rule in the gateway access policy. Endpoint FW rules are defined in old SmartDashboard / Desktop tab or in EPSS...&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 08:25:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Noise-Rule/m-p/65061#M1659</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-10-16T08:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: Noise Rule</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Noise-Rule/m-p/65137#M1663</link>
      <description>&lt;P&gt;We are running Endpoint in the cloud EPMAS (Endpoint Management As A Service).&amp;nbsp; To create Endpoint Firewall rules for the Endpoint client I use SmartEndpoint.&lt;/P&gt;&lt;P&gt;There is no destination field in the Endpoint client Firewall as the destination will always be the workstation/laptop&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 831px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2760iACC23A673927209F/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 842px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2761iA5B4FB4BD143A4E1/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thus the reason for using ports/services.&amp;nbsp;&lt;/P&gt;&lt;P&gt;239.255.255.250 is Simple Service Discovery Protocol (SSDP) port 1900 udp&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 16 Oct 2019 18:37:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Noise-Rule/m-p/65137#M1663</guid>
      <dc:creator>John_Gallagher</dc:creator>
      <dc:date>2019-10-16T18:37:20Z</dc:date>
    </item>
  </channel>
</rss>

