cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

ENS Firewall McAfee/Trellix Applications list update

My question is regarding ENS Firewall under ePO supervision (both versions are actual).

Do You have plans to update the 'McAfee applications' and 'McAfee signed applications' lists with new certificates for your software? Or add the 'Trellix signed applications' set...

An example: the firewall in "block all by default" mode successfully prevents the Agent to communicate with ePO. Yes, the workaround is simple (in+out allowing rules). But, IMO, it would be better to continue to maintain the 'vendor list', which will be actual out of the box.

Thank You!

mafw01.png

3 Replies
Pravas
Employee
Employee
Report Inappropriate Content
Message 2 of 4

Re: ENS Firewall McAfee/Trellix Applications list update

Hi @polezhaevdmi ,

I would like to check on the following.

1. Is ePO on the current build (5.10 CU15 or SP1) ?

2. Is McAfee Core Networking Rules disabled via policy?

We shouldn't need to allow any additional rules as the default works fine.

Thanks

Was my reply helpful?
If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!

Re: ENS Firewall McAfee/Trellix Applications list update

Hello, @Pravas!

Indeed, let's check:

1. Actual, but it still worth to be mentioned - has a long history (this is not the installation 'from scratch') since ePO 5.9 (1-st image);

2. As I see - no (2-nd image). FAQ for Community And Note;

3. At least, I found one previous configuration mistake. The /24 mask will not allow ePO to be concidered in 'trusted network' (3-rd image).

Community is inspiring, let me investigate these rules in-depth more!

Thank You!

VersionsVersions  OptionsOptions

NetworkNetwork

Re: ENS Firewall McAfee/Trellix Applications list update

Finally, as for my case, I found Administrator mistake with particular rule. After rule re-design and mistakes rectification the rule started to work as desired.

Funny fact: if the McAfee trusted application list would be actual, I will not be asked to investigate the rule, and would not find the Administrator mistake.

Still, IMHO, the 'dual variant' with both 'core McAfee/Trellix communication' option, plus, 'McAfee/Trellix trusted application list' - would be much 'durable' due to redundancy.

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from product experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by employees.
Join the Community
Join the Community