When you quarantine an endpoint, the Trellix EDR solution automatically retains connectivity with Trellix products to further investigate and mitigate a threat. Any other network or application services needed to contain or remediate the threat should be identified and excluded from isolation.
If the endpoint is not in Enterprise environment and is connected through VPN, it is essential to retain the VPN service when quarantining the endpoint to continue connected with Trellix products.
Important
Exclude the network connectivity services (for example, VPN service) before quarantining or isolating the endpoint so the endpoint can be accessed.
You can exclude other applications or services from quarantine before or after quarantining the endpoint.
On the ePO - On-prem or ePO - SaaS console, select Menu → Policy → Policy Catalog.
From the Products list, select Trellix EDR with Forensics.
Select the Remediation policy.
Add application paths in the Exclusion section of Containment settings, in the field for the target operating system:
Exclude application paths from containment for Windows — Add application paths including .exe extension to ignore the application from quarantine on Windows endpoints.
Exclude application paths from containment for macOS — Add application paths including .app extension to ignore the application from quarantine on macOS endpoints.
Exclude application paths from containment for Linux — Add application paths to ignore the application from quarantine on Linux endpoints.
For example, you can exclude the VPN client service from quarantine using its application path:
Application path including its .exe extension on Windows endpoints —
C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vacon64.exeApplication path including its .app extension on macOS endpoints —
/Applications/Cisco/Cisco\ AnyConnect\ Secure\ Mobility\ Client.app
Example for Linux:
For ssh process path —
/usr/bin/sshYou can add multiple application paths for excluding applications from quarantine using semicolons (;) to separate entries.
Click Save.
After you create or modify a policy, assign it to the required managed endpoints so that the Trellix EDRF Client applies the configuration.
For more information about assigning a policy to managed endpoints, see ePO - On-prem or ePO - SaaS Product Guide.