Control Windows Firewall
Controls user network using Windows Firewall. When the network sensor is not operating, the agent can be used to add rules corresponding to the node's enforcement policy permissions to the Windows Firewall rule list, thereby performing access control on the endpoint.
- Automatic rule-based outbound traffic blocking by enforcement policy
- Blocking external malicious C&C servers through custom rules
When assigning the plugin, if the Use automatic rule settings option is used, Windows Firewall outbound rules are configured based on the enforcement policy's authorization object information to which the node belongs.
Additionally, you can directly configure Windows Firewall rules with various conditions.
Configuring Windows Firewall Control Options
- Use automatic rule settings: Automatically configures Windows Firewall outbound rules based on the enforcement policy's authorization settings.
- Notification Message: Displays a pop-up message to the user when automatic rules are set.
- Message Content: Enters the content for the pop-up message when automatic rules are set.
- Custom Rules: Allows direct configuration of Windows Firewall rules.
- Use FailSafe: Allows stopping the plugin if connection to the center is impossible.
Configuring Network Blocking Policy via Node Policy
- Go to Policy in the top menu.
- In the left Policy menu, go to Policy > Node Policy > Node Action.
- In the Node Action management window, find and click Windows Firewall Control.
- Enter Condition Settings and options.
- In the left Policy menu, go to Policy > Node Policy.
- Click the node policy to configure the network blocking policy.
- Find Node Action Settings and click Assign.
- In the Available items, find Windows Firewall Control and drag it to the Selected items.
- Click the Add button.
- Click the Modify button.
- Click the Apply Change Policy button in the top right.
Configuring Network Blocking Policy via Enforcement Policy
Step 1. Create Control Target Node Group
- Go to Policy in the top menu.
- In the left Policy menu, go to Group > Node.
- Click Select Action > Create.
- Click the Add button.
- Configure the conditions for the control target and click the Add button.
- Click the Create button.
Step 2. Create Control Action
- In the left Policy menu, go to Policy > Enforcement Policy > Control Action.
- Click Select Action > Create.
- In the Plugin selection item, select the Windows Firewall Control plugin.
- Enter Condition Settings and options.
- Click the Create button.
Step 3. Create Enforcement Policy
- In the left Policy menu, go to Policy > Enforcement Policy > Enforcement Policy.
- Click Select Action > Create and complete the Enforcement Policy Wizard.
- In the Policy Basic Settings tab, enter the Policy ID to use in the ID field.
- In the Node Group Settings tab, select the newly added node group and move it to the Selected item.
- In the Permission Assignment and Control Options tabs, enter the desired options.
- In the Control Action Settings tab, find the created Control Action and move it to the Selected item.
- Click the Complete button.
- Click Apply Change Policy in the top right.