<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Endpoint machine quarantine in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-machine-quarantine/m-p/35308#M869</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When the users malicious request blocked by endpoint blades(Anti-Bot,Antimalware,Threat extraction..),how can I quarantine this machine ? İs there any solution for this issue....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 Mar 2018 14:02:27 GMT</pubDate>
    <dc:creator>Sukru_isik</dc:creator>
    <dc:date>2018-03-13T14:02:27Z</dc:date>
    <item>
      <title>Endpoint machine quarantine</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-machine-quarantine/m-p/35308#M869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When the users malicious request blocked by endpoint blades(Anti-Bot,Antimalware,Threat extraction..),how can I quarantine this machine ? İs there any solution for this issue....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Mar 2018 14:02:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-machine-quarantine/m-p/35308#M869</guid>
      <dc:creator>Sukru_isik</dc:creator>
      <dc:date>2018-03-13T14:02:27Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint machine quarantine</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-machine-quarantine/m-p/35309#M870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume you mean quarantine at the network level with your Check Point gateway.&lt;/P&gt;&lt;P&gt;See&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33727" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33727"&gt;Configuring EndPoint Quarantine Feature&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Mar 2018 23:10:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-machine-quarantine/m-p/35309#M870</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-03-13T23:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint machine quarantine</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-machine-quarantine/m-p/35310#M871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not checkpoint gateway...&lt;/P&gt;&lt;P&gt;I have checkpoint Endpoint Policy Management Server with version R77.30.03 and endpoint security&amp;nbsp; client agent with verison E80.80...&lt;/P&gt;&lt;P&gt;I want to this:&lt;/P&gt;&lt;P&gt;When client download a malicious file or click malicious links, this machine was restricted&amp;nbsp; by endpoint policy management server.&lt;/P&gt;&lt;P&gt;Can I do this ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Mar 2018 08:18:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-machine-quarantine/m-p/35310#M871</guid>
      <dc:creator>Sukru_isik</dc:creator>
      <dc:date>2018-03-16T08:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint machine quarantine</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-machine-quarantine/m-p/35311#M872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you can do this on the Endpoint as well.&lt;/P&gt;&lt;P&gt;&lt;A href="http://downloads.checkpoint.com/dc/download.htm?ID=53788"&gt;From the docs&lt;/A&gt;:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;Endpoint Security can enforce policy rules on computers and users based on their connection and compliance state. When you create a policy rule, you can select the state or states during which this policy is enforced. By default, policies apply when the client is Connected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;States are not applicable for all blades. For example, Full Disk Encryption rules always apply and cannot change based on state. The option to create rules based on state only shows for applicable blades. If there is no applicable rule for the Disconnected or Restricted states, the Connected policy applies.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The &lt;STRONG&gt;Connected&lt;/STRONG&gt; state policy is enforced when a compliant endpoint computer connects to the Endpoint Security Management Server.&lt;/LI&gt;&lt;LI&gt;The Disconnected state policy is enforced when an endpoint computer is not connected to the Endpoint Security Management Server. For example, you can enforce a more restrictive policy if users are working from home and are not protected by organizational resources.&lt;/LI&gt;&lt;LI&gt;The &lt;STRONG&gt;Restricted&lt;/STRONG&gt; state policy is enforced when an endpoint computer is not in compliance with the enterprise security requirements. Its compliance state is moved to Restricted. In the Restricted state, you usually choose to prevent users from accessing some, if not all, network resources. You can configure restricted state policies for these blades:&lt;UL&gt;&lt;LI&gt;Media Encryption &amp;amp; Port Protection&lt;/LI&gt;&lt;LI&gt;Firewall&lt;/LI&gt;&lt;LI&gt;Access Zones&lt;/LI&gt;&lt;LI&gt;Application Control&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Mar 2018 14:49:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-machine-quarantine/m-p/35311#M872</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-03-16T14:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint machine quarantine</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-machine-quarantine/m-p/85164#M2327</link>
      <description>&lt;P&gt;Forensics blade has option called "Machine Quarantine " (image attached).&lt;/P&gt;
&lt;P&gt;Every blade which could trigger a Forensic report could initiate a Restricted state.&lt;/P&gt;
&lt;DIV id="tinyMceEditorMaksym_Sofer_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 07:49:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-machine-quarantine/m-p/85164#M2327</guid>
      <dc:creator>Maksym_Sofer</dc:creator>
      <dc:date>2020-05-14T07:49:02Z</dc:date>
    </item>
  </channel>
</rss>

