Smart Exclusions

Smart Exclusions allows you to add exclusions to one or more capabilities and types easily, whereas the Legacy Exclusions allows you to add exclusion only for one capability at a time.

With Smart Exclusions, you can:

  • Set exclusions to all capabilities and operating systems at once.

  • Use standard syntax across all exclusion types.

  • Use wider range of wildcard characters for nuanced and customized exclusion patterns.

  • Easily enable or disable exclusions with a simple toggle button without the need to delete exclusions temporarily.

Note - Smart Exclusions is supported only with Endpoint Security Client version E87.52 and higher for Windows and E87.50 and higher for macOS.

Adding Exclusions to a Specific Rule

00:00: Smart Exclusions allows you to add exclusions to multiple capabilities easily. An exclusion is an entity, such as an IP address or domain that you want to exclude from the inspection. While, this video specifically details the steps for Harmony Endpoint, it is also applicable to Harmony Browse. 00:19: Log in to the Infinity Portal, access Harmony Endpoint, and click Policy. 00:24: Expand Threat Prevention and click Policy Capabilities and select a . 00:29: In the Capability and Exclusion pane, click Exclusions Center. 00:34: Click "Go To Smart Exclusions". 00:37: You can add an exclusion for a single or multi exclusion type. This video covers the procedure to add an exclusion for a single exclusion type. To add a single exclusion type, click new and select single method exclusion. 00:51: Enter a name for the exclusion and make sure that the status is enabled. 00:56: Select an exclusion type. 00:59: You can either apply the exclusion to all the supported capabilities or to specific supported capabilities. 01:07: Enter the details and click save. 01:10: The new exclusion is added to the table. 01:13: Thank you for watching this video.

To add a new exclusion to a specific rule:

  1. Go to Policy > Threat Prevention > Policy Capabilities.

  2. Select the rule for which you want to create the exclusion.

  3. In the Capabilities & Exclusions pane, click Exclusions Center.

  4. Click Go to Smart Exclusions.

  5. Click or click Create New Exclusion.

  6. Click OK.

  7. Click Save & Install.

  8. Note - You can change Single-method exclusion to Multi-method exclusion. See Managing Exclusions.

Adding Global Exclusions

To add global exclusions that apply to all the rules:

  1. Go to Policy > Threat Prevention > Global Exclusions.

  2. Click Go to Smart Exclusions.

  3. Click or click Create New Exclusion.

  4. Click Save.

    The exclusions are automatically enforced on the client without installing the policy.

  5. Note - You can change Single-method exclusion to Multi-method exclusion. See Managing Exclusions.

Migrating Legacy Exclusions

Best Practice - Check Point recommends to follow these steps before migrating to Smart Exclusions:

  1. Go to Policy > Threat Prevention > Policy Capabilities

  2. Pick a rule to test the migration and clone the rule.

  3. Place the newly created rule at the top.

  4. Under Applied To, select a test group.

  5. Click Exclusion Center for the newly created rule and export the legacy exclusions for backup purposes.

  6. For the newly created rule, migrate to Smart Exclusions. See To migrate legacy exclusions to smart exclusions:.

  7. Click Save and Install.

  8. Go to Logs and filter the logs for the computer in the test group. Verify that there are no false positives and all the detections are excluded correctly. If there are issues, contact Check Point Support.

  9. Perform the steps 1 through 8 for each rule at a time.

  10. Repeat the process for Global Exclusions.

To migrate legacy exclusions to smart exclusions:

  1. To migrate legacy exclusions for a rule:

    1. Go to Policy > Threat Prevention > Policy Capabilities.

    2. Select the rule.

    3. In the Capabilities & Exclusions pane, click Exclusions Center.

  2. To migrate legacy global exclusions, go to Policy > Threat Prevention > Global Exclusions.

  3. Click Go to Smart Exclusions.

  4. To migrate all legacy exclusions:

    1. Click Migrate from Legacy Exclusions (available only if there are no exclusions) or click and click All exclusions from legacy.

      The Import All Legacy Exclusions window appears.

    2. (Recommended) To remove all the legacy exclusions after you migrate to smart exclusions, select Remove all the imported exclusions from legacy.

    3. Click Import.

  5. To migrate specific exclusions:

    1. Click and Select exclusions from legacy.

      The Transfer from Legacy - Select Exclusions window appears.

    2. Select the exclusions.

    3. Click OK.

      The exclusions are added to smart exclusions.

  6. For specific rule, click OK and Save & Install.

  7. For global exclusions, click Save.

    The exclusions are automatically enforced on the client without installing the policy.

Importing and Exporting Exclusions

To import or export exclusions:

  1. To import or export exclusions for a rule:

    1. Go to Policy > Threat Prevention > Policy Capabilities.

    2. Select the rule.

    3. In the Capabilities & Exclusions pane, click Exclusions Center.

  2. To import or export global exclusions, go to Policy > Threat Prevention > Global Exclusions.

  3. Click Go To Smart Exclusions.

  4. To import exclusions:

    1. Click and click Import Files.

    2. Browse and select the import file in the JSON format.

    3. For specific rule, click OK and Save & Install.

    4. For global exclusions, click Save.

      The exclusions are automatically enforced on the client without installing the policy.

  5. To export exclusions, click .

    The file is exported in the JSON format.

Managing Exclusions

To manage exclusions:

  1. To manage smart exclusions for a rule:

    1. Go to Policy > Threat Prevention > Policy Capabilities.

    2. Select the rule.

    3. In the Capabilities & Exclusions pane, click Exclusions Center.

  2. To manage global smart exclusions, go to Policy > Threat Prevention > Global Exclusions.

  3. Click Go To Smart Exclusions.

  4. To edit an exclusion:

    • Select the exclusion and click .

    • Right-click the row and click Edit.

      To a change Single-method exclusion to Multi-method exclusion, click Edit in multi-value wizard at the bottom of the wizard.

      Refer to Adding Exclusions to a Specific Rule to edit the exclusion.

  5. To delete exclusions:

    • Select the exclusions and click .

    • Click the row and at the end of the row, click .

    • Select the exclusions, right-click and click Delete.

  6. To duplicate exclusions:

    • Select the exclusion and click .

    • Click the row and at the end of the row, click .

    • Select the exclusion, right-click and click Duplicate.

  7. To enable or disable the exclusion, toggle the button in the Status column.

  8. To edit Name, Capabilities and Comment:

    1. Click the row.

    2. At the end of the row, click .

    3. Edit the details.

    4. Click .

  9. For a specific rule, click OK and Save & Install.

  10. For global exclusions, click Save.

    The exclusions are automatically enforced on the client without installing the policy.