Configure exceptions that allow network traffic to and from isolated endpoints.
Isolating endpoints is a proven tool for mitigating security incidents. However,
network isolation sometimes hinders incident response, as trusted channels in your
environment are also blocked. The Response Management app allows you to specify
inbound and outbound network traffic exceptions for specific IPv4 addresses.
ImportantYou can only allow network traffic for isolated Windows or macOS endpoints
running Endpoint Sensor or the Apex One Security Agent.
|
Procedure
- Go to and click the Settings tab.
- Enable Allow network traffic on isolated endpoints and
click Edit settings.
Note
If you see View settings, you lack the necessary permissions to edit the settings. - Add a network traffic exception.
- If you need to add a new inbound or outbound exception, click
Add Exception under the Inbound
Network Traffic or Outbound Network
Traffic sections, respectively.
Note
You can specify up to 50 inbound and 50 outbound exceptions. - In the Protocol drop-down list, select which protocol the exception allows.
- In the IP address field, enter the IPv4 address
of the endpoint.
Note
Only standard IPv4 addresses other than 0.0.0.0 are allowed. - In the Port field, specify on which ports to
allow network traffic.
-
Select Any to allow network traffic on any port.
-
Select Specific and enter the ports on which to allow network traffic.Use commas (,) to separate multiple entries.
-
- If you need to add a new inbound or outbound exception, click
Add Exception under the Inbound
Network Traffic or Outbound Network
Traffic sections, respectively.
- In the Status field, choose whether to activate the exceptions after saving.
- Click Save.
Note
-
You must specify at least one inbound or outbound exception to save your settings.
-
The timing of your settings propagating to endpoints depends on the agent.
-
Endpoint Sensor: Exceptions are updated immediately after saving your settings.
-
Apex One Security Agent: Exceptions are updated when the endpoint is isolated.
-
-