Host IP Address Change When Enforcement is Enabled
As a site admin, if you change the IP address of a host when enforcement is already enabled on an agent, there might be an impact if the host IP address is seen in the host firewall rules and catch all is set to deny.
In this scenario, perform the following steps to change the host IP address:
Procedure
1 |
On the Secure Workload UI, Create a new Agent Configuration Profile with enforcement disabled. |
2 |
Create Intent with a list of hosts that require IP address changes, their old and new addresses. |
3 |
Apply the newly created Agent Config Profile to the intent and save the intent. |
4 |
Select the hosts whose IP addresses you want to change and ensure that these hosts have enforcement disabled. |
5 |
Change the IP address of the selected hosts. |
6 |
On the Secure Workload UI, update the filters in the scope by including the new IP addresses of these hosts. |
7 |
Under the tab, verify that the IP address has changed to the new IP address. |
8 |
Under the Policies tab, ensure that the policies are generated with the new IP address. |
9 |
Remove the Intent or Profile created earlier. |
10 |
Click Enable Enforcement to enable the enforcement in the scope for the earlier Agent Config Profile that had enforcement disabled. |