- Log in to the Apex One web console.
- Go to Agents > Global Agent Settings.
- Click the Security Settings tab.
- Go to the Suspicious Connections Settings section.
- Click Edit User-defined IP List.
- On the Approved List or Blocked List tab, click Add to enter the IP address, then click Save.
- To remove IP addresses from the list, select the check box next to the address and click Delete.
- After configuring the lists, click Close to return to the Global Agent Settings screen.
- Click Save to deploy the updated list to agents.
- Log into Apex Central.
- Go to Directories > Product Servers.
- Click the link to open the Apex One as a Service console.
- Go to Agents > Global Agent Settings.
- Click the Security Settings tab.
- Go to the Suspicious Connections Settings section.
- Click Edit User-defined IP List.
- On the Approved List or Blocked List tab, click Add to enter the IP address, then click Save.
- To remove IP addresses from the list, select the check box next to the address and click Delete.
- After configuring the lists, click Close to return to the Global Agent Settings screen.
- Click Save to deploy the updated list to agents.
To verify, you may go to C:\Program Files (x86)\Trend Micro\Security Agent\NcieEcp.ini and check if the IP Address exists under [NCIE Approved List] or [NCIE Blocked List]
If you want to exclude false-positive C&C callback alert notifications, you may refer to Adding C&C callback alerts for individual IP addresses in OfficeScan/Apex One