<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Secure Endpoint (AMP?) isolated network configuring in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-amp-isolated-network-configuring/m-p/4946417#M7933</link>
    <description>Yes. In general it wants an internet connection.  SPP, Behavior and Tetra run without a live connection but all the updates are from the web and much of the console doesn't work without it.  It's all port 443, so standard browser access is enough.&lt;BR /&gt;&lt;BR /&gt;If the workstations are truly isolated, someone needs to get a Cisco Security Sales team involved so you figure out what the customer really needs.&lt;BR /&gt;&lt;BR /&gt;And maybe your team should go to a training class on the product before you go any further.&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Mon, 23 Oct 2023 23:39:48 GMT</pubDate>
    <dc:creator>Ken Stieers</dc:creator>
    <dc:date>2023-10-23T23:39:48Z</dc:date>
    <item>
      <title>Cisco Secure Endpoint (AMP?) isolated network configuring</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-amp-isolated-network-configuring/m-p/4946409#M7932</link>
      <description>&lt;P&gt;I am part of a team doing a deployment for a customer, and they have chosen to use the Cisco Secure Endpoint, Endpoint Protection, AMP, whatever it is called.&amp;nbsp; This is the first problem, because I can't find any consistent documentation for assistance with this installation or configuring.&amp;nbsp; Second, Cisco telephone support is of no use, because I don't have any of the product license information, and they just direct me to a Cisco partner (even though I'm an employee of a Cisco partner, and no one here has ever used this product).&amp;nbsp; Third, the customer doesn't seem to understand the product, and maintains control of it, so I can't actually see how anything is configured for the account or license.&lt;/P&gt;&lt;P&gt;Now that that is out of the way: How can this product be configured for a network that is isolated from the internet by a DMZ, and a firewall?&amp;nbsp; Will all of the installations complain about "no internet"?&amp;nbsp; What components will work?&amp;nbsp; What components won't work?&amp;nbsp; Will there be warning flags on the management web interface for all of the systems that are offline?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 14:58:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-amp-isolated-network-configuring/m-p/4946409#M7932</guid>
      <dc:creator>acfreema</dc:creator>
      <dc:date>2023-10-24T14:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint (AMP?) isolated network configuring</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-amp-isolated-network-configuring/m-p/4946417#M7933</link>
      <description>Yes. In general it wants an internet connection.  SPP, Behavior and Tetra run without a live connection but all the updates are from the web and much of the console doesn't work without it.  It's all port 443, so standard browser access is enough.&lt;BR /&gt;&lt;BR /&gt;If the workstations are truly isolated, someone needs to get a Cisco Security Sales team involved so you figure out what the customer really needs.&lt;BR /&gt;&lt;BR /&gt;And maybe your team should go to a training class on the product before you go any further.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 23 Oct 2023 23:39:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-amp-isolated-network-configuring/m-p/4946417#M7933</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2023-10-23T23:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint (AMP?) isolated network configuring</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-amp-isolated-network-configuring/m-p/4946437#M7934</link>
      <description>&lt;P&gt;In addition to what Ken said you need to make sure that these required server addresses are allowed on your FW or Proxy for your specific region.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Required Server Addresses for Proper Cisco Secure Endpoint &amp;amp; Malware Analytics Operations&lt;/STRONG&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/sourcefire-amp-appliances/118121-technote-sourcefire-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/sourcefire-amp-appliances/118121-technote-sourcefire-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If the client will be not able to reach out to the cloud nothing will work and the service will eventually STOP&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The other thing that your client can consider is Virtual Private Cloud this solution can be either done as virtual machine or physical appliance in either "cloud proxy mode” or “air-gap mode.”&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/fireamp-private-cloud-virtual-appliance/datasheet-c78-742267.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/fireamp-private-cloud-virtual-appliance/datasheet-c78-742267.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; Only physical appliance can be in air-gap mode&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 00:42:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-amp-isolated-network-configuring/m-p/4946437#M7934</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2023-10-24T00:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint (AMP?) isolated network configuring</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-amp-isolated-network-configuring/m-p/4946535#M7935</link>
      <description>&lt;P&gt;Also see the introduction page and deployment strategy guide found here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://console.amp.cisco.com/docs" target="_blank" rel="noopener"&gt;https://console.amp.cisco.com/docs&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If you are a Cisco partner, there are also lots of free training resources available on SalesConnect. See the Black Belt Academy pages where there are specific learning paths for both presales SEs and post sales (deployment) FEs.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 03:11:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-amp-isolated-network-configuring/m-p/4946535#M7935</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-10-24T03:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint (AMP?) isolated network configuring</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-amp-isolated-network-configuring/m-p/4946965#M7940</link>
      <description>&lt;P&gt;Thank you all.&amp;nbsp; This morning, I learned that we aren't actually deploying _everything_ for the Secure Endpoint, just handling the connector installation on all of the systems in the isolated network.&amp;nbsp; Since we are already building the DMZ, and configuring the firewall and proxy, this suddenly became more manageable.&lt;/P&gt;&lt;P&gt;Ken, I completely agree about the additional training.&amp;nbsp; That question is exactly what needed to be asked, because it prompted the revelation above.&amp;nbsp; It is funny how discussing adding time and money to an already in progress project gets better cooperation.&lt;/P&gt;&lt;P&gt;Roman, the customer's internal VM topology and newly learned revised scope don't suggest a virtual private cloud environment.&lt;/P&gt;&lt;P&gt;Marvin, thank you, that looks like a great storehouse of knowledge.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 14:57:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-amp-isolated-network-configuring/m-p/4946965#M7940</guid>
      <dc:creator>acfreema</dc:creator>
      <dc:date>2023-10-24T14:57:41Z</dc:date>
    </item>
  </channel>
</rss>

