We are running an SG-310 with 9.601 as our primary firewall. Endpoint systems behind the 310 also have Carbon Black Defense sensor installed.
When I enable web protection on the SG-310, with only one host in the "allowed networks", many of our endpoint systems with Carbon Black hang and go to 100% CPU utilization. These systems are not on the allowed network list. I have searched the web filter log files for traffic from/to the hanging systems and can't find anything.
Web application control shows traffic to Carbon Black's update site, but it is showing as "pass" which it should be.
Nothing in IPS logs related to these systems.
Any ideas why web filtering would be interfering with Carbon Black sensor software?
Thanks,
Alan Lehman
This thread was automatically locked due to age.