Administrators can configure Apex One to allow, block, or log all connections between agents and user-defined C&C IP addresses.
Note:
The User-defined IP Lists only support IPv4 addresses.
- Go to Agents > Global Agent Settings.
- Click the Security Settings tab.
- Go to the Suspicious Connections Settings section.
- Click Edit User-defined IP List.
-
On the Approved List or
Blocked List tab, add the IP addresses that you want
to monitor.
Tip:
You can configure Apex One to only log connections made to addresses in the User-defined Blocked IP list. To only log connections made to the addresses in the User-defined Blocked IP list, see Configuring Suspicious Connection Settings.
- Click Add.
- On the new screen that appears, type the IP address, IP address range, or IPv4 address and subnet mask for Apex One to monitor.
- Click Save.
- To remove IP addresses from the list, select the check box next to the address and click Delete.
- After configuring the lists, click Close to return to the Global Agent Settings screen.
- Click Save to deploy the updated list to agents.
Parent topic: Suspicious Connection Service
