Examining the firewall logs, I see that endpoint protection uses swi_service.exe which is attempting to communicate on port 80 to access some European AWS addresses. The UTM blocks the traffic by default. This seems like strange behavior. I would have…