TCP Connections To “ent-shasta-rrs-symantec.com”

I do not need a solution (just sharing information)

We have found an enormous amount of blocked traffic on our proxies that is going to tcp://ent-shasta-rrs.symantec.com

I know what the URL is used for, that is not the question.
The big question mark for me is the TCP:// connection that is being blocked. This is expected behaviour by the proxy. Question is why TCP?

The client as in the configuration is using the IE proxy config, which is a PAC-file in the end.
After testing with the URLs listed under https://support.symantec.com/en_US/article.TECH163042.html, I can tell that one of the links is being blocked and the other works.

Is there anyone with an idea why these connections happen?

0

Related:


Leave a Reply