Ask the community

Netskope Client "Blocked Events" are empty - is nothing blocked then?

AQ
Netskope
Netskope

Hello Netskope community members!

 

For those of you who ever wondered what the "Blocked Events" dialog from the Netskope Client is actually tracking - I'll try to explain in a couple of words.

 

AQ_0-1689095599461.png

 

AQ_2-1689096118057.png

 

 

In the Steering Configuration Exceptions (Settings > Security Cloud Platform > Steering Configuration > tenant config > Exceptions) you will find the exceptions that are active for your specific tenant configuration. By default, they are filled up with exceptions that we know can be useful because of TLS decryption issues (certificate pinned apps). Note that these exceptions usually are configured with action "Bypass".

 

AQ_1-1689096042719.png

 

Once you change this action from "Bypass" to "Block" - that's when you tell the client not to Bypass these connection attempts, but actually block them from establishing on the client. And we have no means to track that in the NewEdge DP, since the connection will never reach us as it's already blocked locally. So we will then track them in the Blocked Events in the client on the device itself:

 

AQ_4-1689096946962.png

 

 

AQ_6-1689097152606.png

 

 

AQ_3-1689096904193.png

 

I hope you now understand what events are tracked for which reason in the "Blocked Events" in the context menu of the nsclient.

 

Feel free to comment if you have any remarks!

--
Andy Q | CSE BeNeLux/NEUR/EEUR | Scientists dream about doing great things. Engineers simply execute.
0 Replies 0
Subscribe
Top Liked Authors
Labels

In order to view this content, you will need to sign in to your account. Simply click the "Sign In" button below

Sign In