06-06-2005 06:41 AM - edited 03-10-2019 01:28 AM
Is there a way in the new CSA 4.5 to allow anything to run on a client PC if it came from a specific server? We have a SMS server that needs to be allowed to run whatever it needs to on all our computers. I saw under system state there is a 'network address ranges' but I'm not sure if this would do it or not.
06-06-2005 03:55 PM
We have specific servers that are allowed to connect to hosts and/or run network services on certain ports and we used the network address ranges to make the exceptions.
Hope this helps...
Tom
06-07-2005 04:41 AM
I was told yesterday that the network address ranges under a System State rule applies to the ip address that's running on the client. Is this correct? I need it to apply to server that is trying to run the application or network service on the PC that has the agent running.
06-07-2005 04:19 PM
That's correct but that's not where you would create the rule.
The system state sets define when a system is more or less vulnerable or on a particular network, etc...
What you need to do is identify what SMS actually does and then create rules to allow it. Then you can limit where the SMS contact comes from if you want to.
Tom
06-07-2005 09:59 PM
We also run SMS, and have a File Access Control Rule that allows the Scanwrapper.exe located at @system\CCM\** to prety much do anything it wants.
It seems like Scanwrapper.exe is the initiating process that starts SMS off.
Hope this helps.
Regards
Brad Foy
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide