Jump to content

its possible to use diff. Policies, depending on the Network


Recommended Posts

Hi all,

its possible to configure policies, that they switch settings, depending on the which the endpoint is in ?

 

Example:

a Notebook is in the lokal LAN, with connection to the On-Prem ESET PROTECT Server -> Firewall is off

the same Notebook is in a private LAN Network @ home, so no connection to the local On-Prem ESET Protect Server -> Firewall turns on

 

Greeting from Germany

Link to comment
Share on other sites

Hi, thanks for the fast respont.

 

I know the dyn. Groups, but lets say the Notebook is in the lokal Business Network and has connection to the On-Prem Protect Server, i can create a dyn. Group, wich the notebook joins when the network adapter has a IP Adresse from a configurated Subnet, so far so good.

But if i take the same Notebook after my shift to my home and plugg it in my Homenetwork, then it cant be swapt out off the dyn. groupe for a policie change or ? Bc i have no connection to the On Prem. Server.

 

The idea is:

we have a couple of Notebooks here, a big network with 1XXX Endpoints, X0 Networks/Subnets, 1 On-Prem Protect Server.

As long the Notebook is the company Network, the Firewall is offline (we use medical Equipment and so on), but if the employee take the Notebook on a Business Trip (Airport as example) or for Homeoffice, the Firewall should be turned on (then they use only RDP on any off the Terminal Servers).

 

its thats even possible ?

Link to comment
Share on other sites

  • Administrators

It would work even when roaming with the notebook because polices as well as a list of dynamic groups and the appropriate DG expressions are received by agent when connecting to the ESET PROTECT server and therefore DG work even offline when a connection to the ESET PROTECT server isn't available. The membership in DG is evaluated on clients by the managing agent.

Link to comment
Share on other sites

Hi, me again.

The policie and the evaluation works, thanks again.

But i have a question, it is possible for a DG Group Template to have a Expression with a value "connected to a ESET Protect Server yes/no" or im totally blind today :)

 

Greetings

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...