---
title: "Use case 3: Excluding IP Addresses from Quarantine"
canonical: "https://docs.infoblox.com/space/DeploymentGuideTDIntegrationCiscoISE/1544716770/Use%20case%203%3A%20Excluding%20IP%20Addresses%20from%20Quarantine"
format: markdown
---
Endpoints with IP addresses listed in the `ipRangeToExclude` variable are exempt from quarantine, even if their DNS queries match threat criteria.

Add 10.196.216.19 as value to the variable ‘ipRangeToExclude’ in Data Connector Destination `prod - Ciscoise_TDevents` Configuration.

![image-20250620-050722.png](media://cc8c4dbd-f5cd-4d7e-8c19-27aba6ffec7d)

When the command `dig magdalenawashington[.]net[.]` is executed, the endpoint is **not quarantined** - even though the domain has High severity and High confidence—because its IP address is included in the **ipRangeToExclude** list.