Use the Containment Settings page to control the Endpoint Security (HX) containment feature:
Turn the containment feature on or off.
Identify host sets that should be excluded from containment.
Create a whitelist of IP addresses with which contained host endpoints can still communicate.
Important
Whitelisting only works when there is a direct connection between your host endpoint and a connected system. If your contained host is connected to other systems through the proxy server, you cannot whitelist the contained host IP address.
Turn the containment unlock code feature on or off.
Important
The containment unlock code is supported for Windows agents version 28 or later only. It is not supported for endpoints running Windows XP.
The containment unlock code is supported for macOS agents version 30 or later only.
Set up automatic notification of a host endpoint's containment using either a direct message or a Web page redirect.
See Configuring containment for complete information.
.png)
To access the Containment Settings page, select Containment Settings on the Configure menu.
Admin access
Containment switch
Use the Containment switch at the top of the page to turn the ability to contain hosts on and off.
Note
You cannot turn containment on or off when containment is disabled (DISABLED appears in the Endpoint Security (HX) Web UI). You must first enable containment using the CLI. See Blocking and unblocking access to containment and Turning containment On and Off.
Exclude Hosts list
The Exclude Hosts list shows the host sets currently defined on your appliance. Select a host set to exclude it from containment. See Excluding Host Sets from Containment for more information.
Allowed IP Addresses list
The Allowed IP Addresses list shows the IP addresses with which contained hosts can communicate. You can add or remove IP addresses from this list. See Maintaining the Contained Host Whitelist for more information.
Unlock Code switch
Use the containment Unlock Code switch to turn on and off the ability to request an unlock code from the Endpoint Security (HX) Web UI to remove a host endpoint from containment.
End-User Notification pane
Use the End-User Notification switch at the top of the page to turn automatic notification of containment on and off. You can specify a URL to which hosts are redirected when they are contained or specify a direct message that will be sent to hosts when they are contained. See Notifying end users about host containment for more information.