Trellix recommends that contained hosts be excluded from agent upgrades because the upgrade process will temporarily uncontain the endpoint. The upgrade process allows selected host sets to be excluded from an upgrade.
See the Endpoint Security Agent (HX) Administration Guide for more information.
Contained Hosts in a Proxy Environment
Endpoint Security (HX) version 4.6 or later supports host containment in a proxy environment. Using the Endpoint Security (HX) Web UI, you can contain compromised hosts that use a proxy server to communicate with the Endpoint Security (HX).
Note
Host containment over proxy support is provided for Windows endpoints running Endpoint Security (HX) xAgent version 28 and later, for macOS endpoints running Endpoint Security (HX) xAgent version 30 and later, and for Linux endpoints running Endpoint Security (HX) Agent version 34 and later.
After you upgrade your Endpoint Security (HX) xAgent software to version 28 or later, agent communications are automatically added to the containment allow list. This allows you to contain a compromised host while maintaining communication between the agent and the server through the proxy server. Your contained host will only be able to communicate with the Endpoint Security (HX) through the proxy server. All other communication paths are disabled.
If your host endpoints use a system proxy that has been added to the containment allow list, a contained host will still be able to send and receive web and other traffic. Containment will not work if you are using a system proxy.ENDPT-12648)
Important
The allow list only works when there is a direct connection between your host endpoint and a connected system. If your contained host is connected to other systems through the proxy server, you cannot add the contained host IP address to the allow list.
See your Endpoint Security Agent (HX) Administration Guide for more information on setting up your proxy server and see Maintaining the contained host allow list for more information on containing a Windows host in a proxy environment.