Jump to content

Is allowing ip in trusted zone safe?


Go to solution Solved by Marcos,

Recommended Posts

Hi you

My purpose is just to allow internal PING to check the connection. I have added vlans in the trusted zone. Is this safe? When other machines on the LAN have a local attack, can ESET still detect it?

Link to comment
Share on other sites

  • Administrators

By adding IP addresses to the trusted zone you allow file sharing and some other services in the network. For instance, if you add an IP address of an infected machine that doesn't have ESET installed, a possible rasomware running on the machine could encrypt files in other machines' shares.

Link to comment
Share on other sites

  • Administrators

Create a custom permissive rule for outbound ICMP communication with ICMP type 8 (echo) and the remote IP addresses outside the trusted zone that should be able to ping the machine. Put this custom rule on top of the default firewall rules:

image.png

Link to comment
Share on other sites

  • Administrators

The rule has priority 65, ie. it was not moved on top of the built-in rules. Should the communication be still blocked, you should be able to resolve it though this wizard:

image.png

Link to comment
Share on other sites

How to set rules to priority number 1, I deploy this policy to many machines at once

image.thumb.png.0fd24c2a1b9f5c91458a3b91eaf894ba.png

Link to comment
Share on other sites

  • Administrators
  • Solution
  1. Toggle display of built-in rules
  2. Move the rule on top
  3. Apply the policy setting using the method "replace" or "prepend" so that these rules take precedence over the existing rules on the clients.
Link to comment
Share on other sites

Hi @Marcos

I downloaded the agent file on the eset homepage and installed it on the window server 2012R2 and got the error as shown below.

ESET 1.jpg

image.thumb.png.31f3ea90887a04d3778639a520f3b671.png

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...