Endpoint Protection Firewall blocks virtual machines' DNS requests when using Oracle VirtualBox network bridging
search cancel

Endpoint Protection Firewall blocks virtual machines' DNS requests when using Oracle VirtualBox network bridging

book

Article ID: 164393

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

Symantec Endpoint Protection (SEP) 14 Firewall component blocks DNS requests of a VirtualBox virtual machine when the virtual machine network is set to Bridged. 
"UDP 53 outgoing blocked" is noted for the virtual machine's IP address to the DNS server's IP address. 

debug.log:

====================================================================

2017/01/20 12: 54: 18,656 [4600: 7192] TSE3059: ********* DROP PACKET **********
2017/01/20 12: 54: 18.656 [4600: 7192] TSE: SecurityRule = <Rule_Name>
2017/01/20 12: 54: 18,656 [4600: 7192] TSE3061: *** DROP PACKET ***
2017/01/20 12: 54: 18,656 [4600: 7192] ======= TsPacket ====== BA: 1 == Protocol: 4 ===
=== EtherII-Paket === len: 163 ==== nic: 0 =====
<MAC_Address_Local> ---> <MAC_Address_Remote>, Protocol = 0x800
149DF83C
========= UDP Datagram, len: 149 ====
 

Environment

Symantec Endpoint Protection 14
Oracle VirtualBox 5.1.14 (latest when this article was created on February 8, 2017) and earlier 

Cause

The relevant Smart Traffic Settings should not be turned off, unless for a special reason, as they are necessary to ensure the DNS response packets are allowed by the Firewall.

Resolution

Enable the relevant Smart Traffic Settings in Firewall Policy> Built-in-Rules . The Smart Traffic Settings include Smart Dhcp, Smart Dns, Smart Wins. In most cases, it is sufficient to enable Smart Dns and Smart Wins.