Endpoint containment is a powerful weapon for preventing further compromise by an endpoint. After you have contained a compromised endpoint, it is blocked from communicating with other host endpoints in your enterprise and can only communicate with the Endpoint Security (HX) server and DMZ servers that manage it. You can access and control the containment feature using the Web UI.
Host containment over proxy
Endpoint Security (HX) 4.6 or later supports host containment in a proxy environment for Windows endpoints, Endpoint Security (HX) 4.8 or later supports host containment in a proxy environment for macOS endpoints, and Endpoint Security (HX) 5.2 or later supports host containment in a proxy environment for Linux endpoints. Use the Web UI to contain a compromised host that uses a proxy server to communicate with the Endpoint Security (HX) server.
After upgrading your Endpoint Security (HX) xAgent software to version 29 or later, xAgent communications are automatically added to the containment whitelist. This allows you to contain a compromised host while maintaining communication between the xAgent and the server through the proxy server. If your contained host is connected to other systems through the proxy server, whitelisting the contained host IP address does not work. Your contained host will only be able to communicate with the Endpoint Security (HX) server through the proxy server. All other communication paths are disabled.
Important
Whitelisting only works when there is a direct connection between your host endpoint and a connected system.
A contained host will remain contained as long as the Endpoint Security (HX) xAgent is installed and running on the host endpoint or you remove the host from containment. If the xAgent is shutdown or uninstalled from a contained host, the host is no longer contained.
See "Containing Host Endpoints" in the Endpoint Security (HX) Server User Guide for more information.