Apply Carbon Black EDR Default Firewall Rules
search cancel

Apply Carbon Black EDR Default Firewall Rules

book

Article ID: 431157

calendar_today

Updated On:

Products

Carbon Black Cloud Endpoint Standard

Issue/Introduction

  • How to apply or fix the default firewall rules when the firewall is managed by EDR
  • Misconfigured firewall settings can cause communication issues across an EDR Cluster

Environment

  • Carbon Black EDR Server: All Supported Versions
  • RHEL: All Supported Versions

Resolution

The cbcheck tool can be used to check and apply EDR recommended firewall configurations (Make sure that no custom firewall configurations are needed in environment)

1. Validate and check the missing rules

/usr/share/cb/cbcheck firewall -l

2. Apply any missing rules

/usr/share/cb/cbcheck firewall -a

(In a cluster steps 1 and 2 will need to be done for the Primary node and each minion node in the cluster)

3. Restart services if needed

Additional Information

EDR Firewall Configuration Guide