New installed of KSC11 and KES11.1 blocking firewall

  • 13 May 2019
  • 2 replies

Just upgraded from KSC10 to KSC11 with Agent and KES11 as well. The policy was replicated on the new KSC11 server and most things are alright but we're having an issue with machines running the new version KES11 managed by the new KSC11 server not being able to connect via VPN.

The only events i can see in the logs is-
Event name Network attack detected
Severity: Critical
Application: Kaspersky Endpoint Security for Windows (11.1.0)
Version number:
Task name: Network Threat Protection
Device: LAPTOP1
Group: Test
Time: 13/05/2019 10:03:19
Virtual Administration Server name:
Description: Event type: Network attack detected
Application\Name: Kaspersky Endpoint Security for Windows
User: OPENFIELD\Administrator (Active user)
Component: Network Threat Protection
Result\Description: Blocked
Object: from several different sources
Object\Type: Network packet
Object\Name: from several different sources
Database release date: 13/05/2019 04:41:00

I've added the IP range given by the vpn, which is, into the Firewall as a Local network, i've turned off the Network Threat Protection and i've even turned off the firewall and it still won't let me connect to the VPN. I've also added the vpnagent.exe and vpnui.exe of the Cisco Anyconnect client in as a Trusted Application and again, it stills failed to connect. As soon as i turn off KES11 on the laptop, the vpn connects straight away without issue.

2 replies

All sorted.

It was shockingly web control that was blocking it, the url of abnp.ironport.com was being blocked so just had to unblock it for it to work.
Userlevel 7
Badge +11

I´m glad