Capture Client-Interoperability with DC

Description

This article explains how to configure exclusions on Capture client for the Microsoft Domain Controller.

NOTE: If you deploy this solution, the Capture client (S1 Agent) will not be able to protect the affected endpoints from exploits directed at the application vulnerabilities.



Resolution


Below are the steps to add exclusions for the Microsoft Domain Controller to a specific Device: .


  1. Go to https://captureclient-36.sonicwall.com and login using your MysonicWALL credentials .

  2. Navigate to Assets>Groups>Click on Add .

    Image

  3. Create a Static Group as below specific to the Device thats needs the exclusion to be applied .

    Group Name: DC exclusion 

    Group Type: Device Group
    Group Category:Static

    Image

  4. Click Next to Apply .

  5. In the ADD Devices/Rules page choose the specific device that needs the exclusion to be applied and click Add.

    Image

  6. Click Next to Apply.

  7. Validate the settings on the Summary Page and click confirm to review the policy inherited.

    Image

  8. The Static Group is successfully created , click Done to complete.

    Image

  9. Click on assigned policy for the particular group and you will lead to the policies page . 

    Image

  10. Navigate to Exclusions under Policy and click '+' on the top right of the exclusion page add the Path as required and click Add.

    Image

    General Exclusions for all Windows platforms:

    Pagefile.sys
    *.pst
    C:Windows\System32\Spool
    C:Wiindows\SoftwareDistribution\Datastore
    %allusersprofile%\NTUser.pol%Systemroot%\system32\GroupPolicy\registry.pol

    For Domain Controller Exclusions

    : \ WINNT \ SYSVOL
    : \ WINNT \ NTDS
    : \ WINNT \ ntfrs
    : \ WINNT \ system32 \ dhcp
    : \ WINNT \ system32 \ dns
    : \ WINNT \ ntfrs
    : \ WINNT \ system32 \ dhcp
    : \ WINNT \ system32 \ dns

  11. Navigate to Asset>Device>Choose the specific Device>Settings>Update Policy.

    Image


  12. Also make sure the Policy is updated on the end client as well.

    Image

         



Related Articles

  • Capture Client - System Requirements
    Read More
  • Capture Client – Migrate local CMC user login to MySonicWall account login
    Read More
  • Integration of CFS 5.0 Support in Capture Client
    Read More
not finding your answers?