We have found an enormous amount of blocked traffic on our proxies that is going to tcp://ent-shasta-rrs.symantec.com
I know what the URL is used for, that is not the question.
The big question mark for me is the TCP:// connection that is being blocked. This is expected behaviour by the proxy. Question is why TCP?
The client as in the configuration is using the IE proxy config, which is a PAC-file in the end.
After testing with the URLs listed under https://support.symantec.com/en_US/article.TECH163042.html, I can tell that one of the links is being blocked and the other works.
Is there anyone with an idea why these connections happen?