Kaspersky Industrial CyberSecurity for Networks

Triggering device response actions

July 3, 2024

ID 264569

You can trigger the Isolate device from the network response action and its corresponding reverse action Disable network isolation on a device. To manage network isolation, the device must run Kaspersky Endpoint Agent prepared according to the scenario for preparing to receive data from EPP applications.

To trigger a response action for a device:

  1. Connect to the Kaspersky Industrial CyberSecurity for Networks Server through the web interface using the Administrator account.
  2. Select the device in the Assets section on the Devices tab or in the Network map section.

    In the Network map section, you can select the device on both the network interactions map and the topology map.

    The details area appears in the right part of the web interface window.

  3. In the details area, open the Threat response drop-down list and select the appropriate item:
    • Isolate device from the network — if you want to isolate the selected device from the network.
    • Disable network isolation — if you want to disable network isolation of a device for which the Isolate device from the network action was previously triggered.

    Items in the Threat response drop-down list are available if Kaspersky Endpoint Agent is installed on the device.

    A window with a confirmation prompt opens.

  4. In the request window, confirm the start of the response action.

The application will register a new response action. You can view information about this action in the Events section on the Response actions tab.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.