Maintaining the contained host allow list

Prev Next

By default, contained hosts can only communicate with the Endpoint Security (HX). By creating a contained host allow list, you allow contained hosts to communicate with specified IP addresses and hostnames.

Adding hosts to the allow list only works when there is a direct connection between your host endpoint and a connected system. If your contained host is connected to other systems through the proxy server, you cannot allow list the contained host IP address.

Important

Using DNS names instead of IP addresses in your server allow list can cause problems in some scenarios for a contained host. Ensure your server list (Admin > Policies > Agent Default policy > Server Address) contains the IP address of your Endpoint Security (HX) Server.

A contained host will remain contained as long as the Endpoint Security (HX) xAgent is installed and running on the host endpoint or you remove the host from containment. If the agent is shut down or uninstalled from a contained host, the host is no longer contained.

Important

If an allow listed host's IP address changes after a host endpoint is contained, the endpoint will not be able to contact the allow listed host.

To ensure that contained hosts on a VPN connection continue to communicate with the Endpoint Security (HX), add the IP address for your VPN to the containment allow list. If the VPN IP address is not allow listed, Endpoint Security (HX) requests, including containment cancellation requests, do not reach the host endpoint because the VPN connection is disrupted after containment occurs.

This section describes how to manage your contained host allow list:

Prerequisites
  • Admin access