DCE-RPC traffic is dropped on High Ports
||R77, R77.10, R77.20, R77.30, R80.10
|Platform / Model
- SmartView Tracker logs show that DCE-RPC traffic on High Ports is dropped, although a rule with the ALL_DCE_RPC service exists.
- The DCE-RPC traffic is matched to a rule that allows traffic on TCP port 135 and located above the rule with the "ALL_DCE_RPC" service.
- The RPC initiator (traffic on TCP port 135) must pass through the Security Gateway on the "ALL_DCE_RPC", so the session "real" traffic on the higher port will pass.
Note: To view this solution you need to