Kaspersky Endpoint Security 12 for Linux

Configuring network isolation exclusions

July 22, 2024

ID 272820

You can configure exclusions:

Network connections that are covered by the configured rules remain unblocked on the device after network isolation is enabled.

By default, network profiles consisting of rules that ensure uninterrupted operation of devices with the DNS/DHCP server and DNS/DHCP client roles are excluded from network isolation.

Exclusions defined in policy properties are applied only if network isolation is automatically enabled by the application as a result of reacting to the detection of indicators of compromise (IOC).

Exclusions defined in device properties are applied only if network isolation is manually enabled in the device properties or in the alert details window.

An active policy does not prevent the network isolation exclusions defined in the device properties from being applied.

You can view the list of network isolation exclusions:

  • In the policy properties (Application settingsDetection and ResponseEndpoint Detection and Response OptimumExclusions link)
  • In the device properties (Assets (Devices)Managed devices → <device name> link → <name of the Kaspersky Endpoint Security application> link Application settingsDetection and ResponseEndpoint Detection and Response OptimumExclusions link)
  • in the command line

In this section

Adding or removing network isolation exclusions in policy properties in the Web Console

Adding or removing a network isolation exclusion in device properties

The network isolation exclusion adding window

The Network profiles dictionary window

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.