<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exclude/whitelist a source server IP address in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/exclude-whitelist-a-source-server-ip-address/m-p/3732030#M257</link>
    <description>You're absolutely right. We are having performance issues when KACE is deploying updates. So I have granted exclusions for the KACE processes (konea.exe, runkbot.exe, kdeploy.exe, and kpatch.exe) and also the folder location where KACE agent downloads those update packages. I have to see in the next few weeks if this makes a difference in deploying updates. Thanks so much for the information.</description>
    <pubDate>Wed, 24 Oct 2018 20:01:09 GMT</pubDate>
    <dc:creator>verasme</dc:creator>
    <dc:date>2018-10-24T20:01:09Z</dc:date>
    <item>
      <title>Exclude/whitelist a source server IP address</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whitelist-a-source-server-ip-address/m-p/3730221#M253</link>
      <description>&lt;P&gt;Is there a way to either whitelist or create an exclusion in Cisco AMP so that anything coming from that IP address or server is ignored by the Cisco AMP agent? We have a KACE appliance that downloads Windows updates to the clients and I would like to make an exception so that anything coming from our KACE appliance is accepted by Cisco AMP. We find that Cisco AMP takes a significant percentage of the client-side CPU when KACE agent is downloading Windows updates.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:06:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whitelist-a-source-server-ip-address/m-p/3730221#M253</guid>
      <dc:creator>verasme</dc:creator>
      <dc:date>2020-02-21T05:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude/whitelist a source server IP address</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whitelist-a-source-server-ip-address/m-p/3730403#M254</link>
      <description>Yes you can exclude it from AMP policy in the cloud and the users agent&lt;BR /&gt;will download that.&lt;BR /&gt;&lt;BR /&gt;See this&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/sourcefire-fireamp-endpoints/118341-configure-fireamp-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/sourcefire-fireamp-endpoints/118341-configure-fireamp-00.html&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 23 Oct 2018 05:46:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whitelist-a-source-server-ip-address/m-p/3730403#M254</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2018-10-23T05:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude/whitelist a source server IP address</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whitelist-a-source-server-ip-address/m-p/3730754#M255</link>
      <description>&lt;P&gt;I don't see anything in that article that talks about excluding IP addresses. Can you point me in the right direction?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 13:39:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whitelist-a-source-server-ip-address/m-p/3730754#M255</guid>
      <dc:creator>verasme</dc:creator>
      <dc:date>2018-10-23T13:39:37Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude/whitelist a source server IP address</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whitelist-a-source-server-ip-address/m-p/3732025#M256</link>
      <description>&lt;P&gt;There is no way to tell AMP to ignore&amp;nbsp;&lt;STRONG&gt;everything&lt;/STRONG&gt; by specifying an IP address or domain. &amp;nbsp;The IP Whitelist feature (under Outbreak Control in the AMP console) is just for overriding a block based on the Cisco intelligence feed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on your description, what you need here is a way to reduce or eliminate the performance impact when the KACE agent on an endpoint performs updates, correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If so, the generally recommended way to do that is with an&amp;nbsp;&lt;STRONG&gt;exclusion&lt;/STRONG&gt; (found under Management in the console) instead of a whitelist. &amp;nbsp;That's what the original link talked about, and you can set an exclusion based either on a&amp;nbsp;location in the file system, or the process that is performing the operations. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you need assistance with the exclusion process, or with other performance issues, my advice&amp;nbsp;is to&amp;nbsp;open a support case, and be sure that it gets routed to the AMP TAC specialists. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 19:56:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whitelist-a-source-server-ip-address/m-p/3732025#M256</guid>
      <dc:creator>brmcmaho</dc:creator>
      <dc:date>2018-10-24T19:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude/whitelist a source server IP address</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whitelist-a-source-server-ip-address/m-p/3732030#M257</link>
      <description>You're absolutely right. We are having performance issues when KACE is deploying updates. So I have granted exclusions for the KACE processes (konea.exe, runkbot.exe, kdeploy.exe, and kpatch.exe) and also the folder location where KACE agent downloads those update packages. I have to see in the next few weeks if this makes a difference in deploying updates. Thanks so much for the information.</description>
      <pubDate>Wed, 24 Oct 2018 20:01:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whitelist-a-source-server-ip-address/m-p/3732030#M257</guid>
      <dc:creator>verasme</dc:creator>
      <dc:date>2018-10-24T20:01:09Z</dc:date>
    </item>
  </channel>
</rss>

