Network isolation lets you isolate potentially compromised endpoints from the rest of your network using the Trend Vision One extended detection and response (XDR) interface.
If you connect your agents and relays to the primary security update source via a proxy, network isolation automatically uses the same proxy settings.

Requirements Parent topic

Workload Security uses an IoT mechanism to transmit messages and events to Trend Vision One XDR. If you need to restrict the URLs allowed in your environment, configure your firewall to include the Event Channel - XDR Activity Monitoring FQDNs from the Workload Security URLs table.

Isolate endpoints using network isolation Parent topic

To isolate endpoints using Network Isolation:

Procedure

  1. Trigger Network Isolation
  2. Create an Isolate Endpoint Task
  3. Monitor task status

What to do next

Trigger network isolation Parent topic

After identifying the endpoint to isolate, you can trigger network isolation from one of the following:
  • From the Trend Vision One Search App icon-vision-one-searchapp=d75f2424-91f4-428d-80c1-df6dd7ab20f9.png:
    Right-click on the endpointHostName for the endpoint you want to isolate and select Isolate Endpoint.
    network-isolation-trigger-searchapp=b244e338-8c1e-44ac-9bb9-5eebb9d733b6.png
    The Isolate Endpoint Task window appears.
  • From the Trend Vision One Workbench (under XDR icon-vision-one-XDRsidebar=fa1898ae-8d66-4b25-810e-56a9be34a661.png):
    Right-click on the server icon icon-vision-one-server=a2cc4836-09aa-4c1e-a259-b2454370e73b.png for the endpoint you want to isolate and select Isolate Endpoint.
    network-isolation-trigger-workbench=8050301e-bfb4-43cd-bb59-198bf3d562d5.png
    The Isolate Endpoint Task window appears.
  • From the Trend Vision One Observed Attack Techniques tab (under XDR icon-vision-one-XDRsidebar=fa1898ae-8d66-4b25-810e-56a9be34a661.png):
    Right-click on the "Associated endpoint" that you want to isolate and select Isolate Endpoint.
    network-isolation-trigger-observedattacktechniques=8312bcda-8233-4776-8ea0-1008c91aaefb.png
    The Isolate Endpoint Task window appears.

Create an Isolate Endpoint Task Parent topic

From the Isolate Endpoint Task window:

Procedure

  1. Optionally, enter a description for the task.
  2. Select Create to start the task.
    network-isolation-createtask=aadfb0f0-5b74-4eea-90db-4d5858c5bdde.png

Monitor task status Parent topic

You can monitor tasks from Response Management icon-vision-one-responsemanagementapp=5702fe14-c9e9-4c1b-9ee6-379ec4118ed5.png.
Task status indicates whether or not the managing server was able to successfully receive and execute a command. If the command target is a Security Agent, the Task status does not necessarily indicate that the target Security Agent or object successfully executed the command.
Task statuses include:
  • icon-file-collection-taskstatus-inprogress=69c509c6-f8a4-4476-b3b8-9713f2996b22.png In progress: Trend Vision One sent the command to the managing server and is waiting for a response.
  • icon-file-collection-taskstatus-queued=e693483e-1037-4854-b2e0-e72f47bd77eb.png Queued: The server queued the command due to a high volume of requests or because the Security Agent was offline.
  • icon-file-collection-taskstatus-successful=2203e0bf-74f5-4100-a120-a2b70cfd8dd3.png Successful: The managing server successfully received the command.
  • icon-file-collection-taskstatus-unsuccessful=71b8f3a4-491b-4e5f-a715-c317bf9e6a7d.png Unsuccessful: An error or time-out occurred when attempting to send the command to the managing server.
You can locate tasks by using the Search field or selecting Isolate Endpoint from the Action list.

Restore connection to an endpoint Parent topic

After resolving the security issues on an isolated endpoint, you can restore its network connectivity from Response Management icon-vision-one-responsemanagementapp=5702fe14-c9e9-4c1b-9ee6-379ec4118ed5.png.
Select the options button network-isolation-optionsbutton=93d79e5e-835f-4656-af91-266b59672cd8.png beside the endpoint and select Restore Connection.
network-isolation-restoreconnection=fa245ae0-e58c-468f-8ae6-22a99b92a912.png

Troubleshoot common issues Parent topic

To troubleshoot common issues triggering Network Isolation or Restore Connection, check the following settings in your Workload Security console:

Trend Vision One settings Parent topic

In the Trend Vision One (XDR) tab (Administration System Settings Trend Vision One (XDR)), make sure that:
  • Enrollment status is Registered
  • Forward security events to Trend Vision One has its checkbox selected
remote-shell-XDR-and-log-forwarding=b22cfe2e-110f-46fe-93dd-20c35c5586ba.png

Security module settings for your computers Parent topic

In the Activity Monitoring tab for your computers (Computers (Right- or- double-click) Details Activity Monitoring General), make sure Configuration is set to On or Inherited (On).
remote-shell-activitymonitoring=b66e7b2d-8fe6-4bd8-9d45-ee3469c8f058.png
You can also enable Activity Monitoring for computers by enabling it in the policy assigned to them. From the Policies tab, double-click the policy for which you want to enable Activity Monitoring. Go to the Activity Monitoring General and make sure that Activity Monitoring State is set to On.
If you have checked the requirements and troubleshoot common issues sections, but are still experiencing problems, contact support.