Jump to content

GLFI69

Members
  • Posts

    87
  • Joined

  • Last visited

Posts posted by GLFI69

  1. Hello, i have the KSC 11 on a Server 2008 R2 SP1 with SQL Express 2008 R2.

    Yes, i have to upgrade the server 2008 R2 but for now i would like to upgrade and next i will move the KSC 12 on a server 2019.

    In the KSC 12 system requirements i can’t see Windows Server and SQL 2008 R2 compatibility because their support is ended but is there anyone who has a system like mine and tried to update to KSC 12?

    Thanks.

  2. Hi, I'm trying to apply and activate the “out of office” policy on my notebook.
    I copied the exixting policy, I defined it as "out of office" (no inheritance is active), I deactivated the Application Control, I waited for the new policy/settings to be propagated to the notebook, I unplugged the network cable and connect it to the internet with an LTE usb modem.
    I think that my notebook is definitely "out of office" but the out of office policy has not been activated.
    I should have seen Application Control deactivate with the activation of the offsite policy.
     From the Kaspersky documentation it seems that there is nothing else to do.
     Do you have any explanation?
     I use KES 11.2.0.2254 cf1.

  3. Salve, stamattina sto provando l’attivazione del criterio fuori sede sul mio notebook.

    Ho copiato il criterio esistete, l’ho definito come “fuori sede” (nessuna ereditarietà è attiva), ho disattivato l’Application Control, ho aspettato che le nuove impostazioni venissero propagate al notebook, ho staccato il cavo di rete e ho inserito un modem usb per connettermi a Internet.

    Direi che sono decisamente “fuori sede” ma il criterio fuori sede non si è attivato.

    Nel senso che avrei dovuto vedere l’Application Control disattivarsi con l’attivazione del criterio fuori sede.

    Dalla documentazione Kaspersky sembra che non ci sia nient’altro da fare.

    Avete qualche spiegazione?

    Uso il KES 11.2.0.2254 cf1.

  4.  

    Hello, a few minutes ago i received an email alert for an attempt to encryption file and i checked immediately on the file server.

    By KS Server settings, access to the file server should be blocked from this workstation for 59 minutes and so it would seem by looking at the KS server local console on the server.

    But after i open the KS server console, i cannot see any host blocked and the workstation can ping and access the file server.

    I’m using KS for server 10.1.2.992.

    is it a malfunction or did I miss some configuration?

    This is the mail alert:

    Si è verificato l'evento Encryption attempt detected sul computer FileServerName del dominio XXXXXXX alle venerdì 7 febbraio 2020 12:29:07 (GMT+01:00) Object detected:  HEUR:Generic.Unknown.Cryptor. Object name: FilePath\Gestione\ATTIVITA'-INFO-SCADENZE\Modulistica Inf-Oss-Fkt\MODULISTICA CUCINA\Mod127.12 Raccolta preferenze ospiti.xls. User: S-1-5-21-954386897-3593868654-4004073292-1270

    These are configuration e console images:

     

  5. Hello Ivan, i have not blocked any wi-fi bus.

    KES blocks wi-fi bus instead of checking the wi-fi network you are trying to connect to.

    The policy under “Device type” is exactly as you see it in the screenshot.

    I double clicked "wi-fi" and entered the trusted wi-fi networks.

    I have tried that policy on three different notebooks and the result does not change.

    I have opened a ticket with kaspersky support: INC000011236116.

  6. Hello, i would like to prevent certain devices from connecting to unauthorized wi-fi networks (such as smartphone hotspots).

    Under "Device Control" I activated the restrictions by entering the SIDs of the allowed wi-fi networks but the Notebook i’m testing can‘t connect because KES blocks the Wi-FI bus:

    Si è verificato l'evento Connessione dispositivo bloccata sul computer NAME del dominio XXX alle giovedì 30 gennaio 2020 14:10:39 (GMT+01:00)

    Tipo evento:     Connessione dispositivo bloccata

    Dispositivo\Categoria dispositivo:     Dispositivo

    Dispositivo\Tipo di dispositivo/tipo di bus:     Wi-Fi

    Dispositivo\ID dispositivo:     PCI\VEN_168C&DEV_0032&SUBSYS_E044105B&REV_01\4&b40b749&0&00E0

    Utente:     XXX\USERNAME (Non definito)

    Risultato\Decisione:     Blocca

    Risultato\Operazione:     Connetti

     

    I can’t add this bus to the trusted devices in “Device Control” because when i serach with the Notebook name that bus is not listed.

     

     

    I have no other active exclusions in “Device Control” of this policy.

    This is the policy:

     

×
×
  • Create New...