10-12-2018 12:37 PM
Hi there,
I would like to use the Anomalous Behaviour with automatic enforcement, but would like to allow changes from Windows to Linux and Linux to Windows.
From the documentation it seems that this change will trigger "anomalous behaviour".
Is there a way to circumvent this issue (ex: only use main classes like Workstation to Printer, and allow changes inside the same class)?
Thanks
Solved! Go to Solution.
10-15-2018 08:16 AM
It will depend on whether the Linux will send DHCP Vendor Class ID. AFAIK, most Linux doesn't send Vendor Class ID so the endpoint will be profiled as WIndows and not trigger the ABD.
10-15-2018 05:03 AM
Hmm, I am also curious about this. I've seen very little documentation regarding Anomalous Behavior and the ability to write good policy.
10-15-2018 08:16 AM
It will depend on whether the Linux will send DHCP Vendor Class ID. AFAIK, most Linux doesn't send Vendor Class ID so the endpoint will be profiled as WIndows and not trigger the ABD.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide