Views:
 
This feature requires special licensing: Endpoint Detection & Response (EDR) Add-On
 
To isolate the endpoint, do the following:
  1. Log in to the WFBS-SVC web console.
  2. Go to SECURITY AGENTS.
  3. Find the machine you want to isolate then click the endpoint name.
  4. The endpoint details will show. Click Task > Isolate Endpoint.

    Module state

  5. Wait for the agent to receive the network isolation command.

    Module state

  6. Once the agent is isolated, you will see the following changes on the web and agent console -

    The endpoint name in the web console will have the disconnected icon:

    Module state

    The agent main console will have endpoint isolated icon:

    Module state

 
Isolated endpoints lose network access and can only communicate with the Worry-Free Services server.
 

To allow network traffic between isolated endpoints and other management tools:

  1. Go to POLICIES > Global Security Agent Settings.
  2. Click Isolated Endpoints.
  3. To add an exception, click Add and specify the IP address, protocol, and ports.
  4. To edit an exception:
    • IP addresses or ports: Click the IP address or port and update the setting.
    • Protocols: Click the Protocol list and select a protocol.
  5. To delete an exception, click the trash icon.
  6. Click Save.

To restore the connection of the isolated endpoint, do the following:

  1. Find the isolated machine then click the endpoint name.
  2. The endpoint details will show. Click Restore Connection.

    Module state

  3. Wait for the agent to receive the network restore command.

    Module state

  4. Once the network of the isolated endpoint is restored, the network access will be back to normal.