Alright, so we’ve been running Perimeter 81 for about six months now. Mostly smooth, except for this one gnarly issue that keeps popping up like a bad penny.
Our Windows fleet (mix of Win 10 and 11, enterprise builds) has CrowdStrike Falcon as the endpoint AV. Every few weeks, on a seemingly random subset of machines, the Perimeter 81 agent decides to have a turf war with it. The symptoms are classic: sudden loss of network connectivity while the VPN is active, system tray icon showing "connected" but all traffic is dead, or the machine just blue-screening (KMODE_EXCEPTION_NOT_HANDLED, often pointing to network drivers).
We’ve tried the obvious: adding the Perimeter 81 directories and processes to the CrowdStrike exclusion list, running both as admin, ensuring all drivers are signed. Support’s go-to answer is "update to the latest agent," which we do religiously, but the conflict seems to resurface after a few quiet weeks. It's like they play nice until a background update tweaks something on either side.
I'm curious if anyone else has mapped this minefield more successfully. Specifically:
- Is there a known problematic driver or service (P81 NetFilter, etc.) that we should be more aggressive with in our AV policies?
- Any registry tweaks or group policy adjustments that actually stick?
- Has anyone gotten a straight answer from either vendor on *which* component is actually causing the handle conflict or memory leak?
We're running A/B tests on different AV exclusion configurations right now, but it's frustrating to treat the symptom instead of the root cause. The data pipeline for our experiment logs is filling up with "another machine dropped from the cohort" alerts.
Data over dogma.