This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Block clients with no heartbeat

Hello,

can someone please describe in a few words, what "Block clients with no heartbeat" really does?
The one-liner from the online help does'nt really say more than as is shown on the rule options.
I have a problem to understand how this check-box makes sense, when I already select: Minimum HB permitted: GREEN



This thread was automatically locked due to age.
Parents Reply Children
  • If the rule applies (First match), XG considers your filter on the rule. 

    The firewall rule and all things will be applied, no matter what. 

    If the minimum HB is not met, it will be blocked.(You select minimum green, the client is RED). 

    If the client does not HB and you select, block Client with no HB, it will be blocked.

  • sorry, I don't get it

    Cannot see, how it really is useful in a real world scenario. Maybe I have to read your lines tomorrow again and have an anlightenment then. ;-)

  • "Block Clients without Heartbeat" = NAC with Sophos Endpoint.

    Green/Yellow/No Restriction Minimum = In Case you clients only with a certain HB status in your network communicating. 

    You need only one rule. Its not a selection criteria, instead only a on top control feature for your desired network.

    You want only HB Clients to communicate through XG? Select the checkbox, XG will block everything else, what does not have a Endpoint installed. 

    You want only green HB Clients talking to WAN? Select green as minimum requirement and block everything without. 

    You have a mixed setup, some clients with EP, some without in one network. Dont select to block Clients without and use HB only if available. 

  • Thanks LuCar Toni.

    So in this example I have indeed a mix of devices with and without HB that need to access a server.

    Now this rule has been created by some other admin here:

    Will a user of a device without HB be allowed to access the server? It should, right?

    Only if the device had HB but was marked as HB RED, it would be denied, true?

  • That correct. The User with no Endpoint installed should be able to use this rule.