Agent containment allows traffic based on protocol and IP address. Ports are also used to control traffic. When you enable host containment at the lowest layer, traffic is limited to the following:
Ethernet or WirelessWAN (WirelessWan is used by cell providers to allow for access to cell networks for Internet access.)
UDP port 67 and DHCP port 68 is allowed to ensure that those using DHCP do not lose their IP address reservation while the host is contained.
TCP traffic over IP addresses defined by the Agent whitelist.
ICMP type 9 router advertisement and type 10 router solicitation.
Note
The Endpoint Security (HX) Server IP address is always included in the whitelist.
.png)
You must whitelist the agent process ID to allow traffic from any contained Windows agent, and any contained macOS agent version 30 and later, as well as any Linux agent version 34 and later, that uses a proxy server to communicate with the Endpoint Security (HX) Server version 4.8 and later.
If you are using an agent proxy and you want to be able to contain compromised hosts, you must set up the proxy server with a separate IP address that can only be used to reach the Endpoint Security (HX) Server. This separate IP address can be defined in the Endpoint Security (HX) Server whitelist. This will allow communication between the host endpoint and the Endpoint Security (HX) Server while blocking all other communication flows from the contained endpoint agent. See Excluding Agent Files in Your Antivirus Software for more information.
.jpg)
.jpg)
Use the Endpoint Security (HX) Web UI to add the proxy server IP address to the Allowed IP Addresses on the Containment Settings page. See the Endpoint Security (HX) Server User Guide for more information.