<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AMP for Endpoints -SQL CSV  (cluster store volumes) issues in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-sql-csv-cluster-store-volumes-issues/m-p/4173823#M5751</link>
    <description>&lt;P&gt;I believe we were able to resolve this by creating a new policy for just those servers and disabling the Malicious Acitivity Protection option.&lt;/P&gt;</description>
    <pubDate>Mon, 26 Oct 2020 17:00:53 GMT</pubDate>
    <dc:creator>techytuesday</dc:creator>
    <dc:date>2020-10-26T17:00:53Z</dc:date>
    <item>
      <title>AMP for Endpoints -SQL CSV  (cluster store volumes) issues</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-sql-csv-cluster-store-volumes-issues/m-p/4173781#M5747</link>
      <description>&lt;P&gt;We are having issues with AMP for Endpoints installed on Windows Server 2012 R2&amp;nbsp; servers with SQL clustering.&lt;/P&gt;&lt;P&gt;it appears the cluster volume store is not accessible by the cluster if AMP is installed.&amp;nbsp; We have not implemented any exclusions other than the CISCO maintained exclusions at this point.&amp;nbsp; &amp;nbsp;Does anyone have any recommendations for solving this issue?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2020 15:53:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-sql-csv-cluster-store-volumes-issues/m-p/4173781#M5747</guid>
      <dc:creator>Davedog</dc:creator>
      <dc:date>2020-10-26T15:53:59Z</dc:date>
    </item>
    <item>
      <title>Re: AMP for Endpoints -SQL CSV  (cluster store volumes) issues</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-sql-csv-cluster-store-volumes-issues/m-p/4173823#M5751</link>
      <description>&lt;P&gt;I believe we were able to resolve this by creating a new policy for just those servers and disabling the Malicious Acitivity Protection option.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2020 17:00:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-sql-csv-cluster-store-volumes-issues/m-p/4173823#M5751</guid>
      <dc:creator>techytuesday</dc:creator>
      <dc:date>2020-10-26T17:00:53Z</dc:date>
    </item>
    <item>
      <title>Re: AMP for Endpoints -SQL CSV  (cluster store volumes) issues</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-sql-csv-cluster-store-volumes-issues/m-p/4175878#M5762</link>
      <description>&lt;P&gt;Thank you. We checked with Cisco and indeed disabling MAP (not placing in audit, but disabling) worked and in fact MAP is not recommended by Cisco for server deployments.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 15:05:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-sql-csv-cluster-store-volumes-issues/m-p/4175878#M5762</guid>
      <dc:creator>Davedog</dc:creator>
      <dc:date>2020-10-29T15:05:11Z</dc:date>
    </item>
    <item>
      <title>Re: AMP for Endpoints -SQL CSV  (cluster store volumes) issues</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-sql-csv-cluster-store-volumes-issues/m-p/4176059#M5769</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/883368"&gt;@Davedog&lt;/a&gt;,&lt;BR /&gt;glad to here you solved your problem. BTW, for servers with high network activity you may install the endpoint with the /skipdfc 1 option. This skips the installation of the network drivers.&lt;/P&gt;
&lt;P&gt;In addition, to figure out what is going on with the endpoint, you can use the following tools.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://github.com/CiscoSecurity/amp-05-windows-tune" target="_blank"&gt;https://github.com/CiscoSecurity/amp-05-windows-tune&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://github.com/CiscoSecurity/amp-05-health-checker-windows" target="_blank"&gt;https://github.com/CiscoSecurity/amp-05-health-checker-windows&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Greetings,&lt;BR /&gt;Thorsten&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 19:07:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-sql-csv-cluster-store-volumes-issues/m-p/4176059#M5769</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2020-10-29T19:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: AMP for Endpoints -SQL CSV  (cluster store volumes) issues</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-sql-csv-cluster-store-volumes-issues/m-p/4176090#M5773</link>
      <description>&lt;P&gt;This isn't really a solution though. It works but disabling MAP leaves you vulnerable to ransonware.&amp;nbsp; Its the only thing that has worked from what I have seen.&amp;nbsp; We install the client on servers with the /skipdfc 1 switch and Device Network Flow correlation is not enabled on the policy.&amp;nbsp; Thorsten, since you are a Cisco employee do you know or have seen in the knowledge base any other way to make this work without disabling MAP.&amp;nbsp; Its more of a workaround not really a solution.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 19:48:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-sql-csv-cluster-store-volumes-issues/m-p/4176090#M5773</guid>
      <dc:creator>techytuesday</dc:creator>
      <dc:date>2020-10-29T19:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: AMP for Endpoints -SQL CSV  (cluster store volumes) issues</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-sql-csv-cluster-store-volumes-issues/m-p/4176264#M5776</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/879022"&gt;@techytuesday&lt;/a&gt;,&lt;BR /&gt;true, disabling an engine or having multiple exclusions raises the attack surface. Regarding Ransomware, what i´m always thinking about is, how it should get active on a system, which, i assume, is not fully connected to the the internet, where most time no user is logged on, no mails and no other user activity. Finally, what is the real risk that Ransomware gets active on my server?&lt;/P&gt;
&lt;P&gt;As outlined in the policy object, Development recommends to disable MAP engine on servers.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bildschirmfoto 2020-10-30 um 08.14.21.png" style="width: 198px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/87397i67811D22F031B1DB/image-dimensions/198x133?v=v2" width="198" height="133" role="button" title="Bildschirmfoto 2020-10-30 um 08.14.21.png" alt="Bildschirmfoto 2020-10-30 um 08.14.21.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;You may enable the new &lt;STRONG&gt;Behavioral Protection Engine&lt;/STRONG&gt; to close this gap.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Behavioral Protection Engine - schematically view" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/87398iC2F86C9EEAB558E0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot APDE Engine schematic representation-V3 (1).png" alt="Behavioral Protection Engine - schematically view" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Behavioral Protection Engine - schematically view&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Greetings,&lt;BR /&gt;Thorsten&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 07:19:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-sql-csv-cluster-store-volumes-issues/m-p/4176264#M5776</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2020-10-30T07:19:06Z</dc:date>
    </item>
  </channel>
</rss>

