For the complete documentation index, see llms.txt. This page is also available as Markdown.

Firewall rule management

In the view IT Management > Firewall you can review created rules, check their deployment status, and create, edit, copy, and delete configurations.

Widok reguł zapory z informacją o komputerze, statusie wdrożenia, akcji i profilu sieci.
Firewall rules view with information about the computer, deployment status, action, and network profile.

Information available in the rules list

The table presents the most important parameters of each rule, including:

  • Rule - the name of the created configuration.

  • Computer - the device on which the rule was assigned.

  • Deployment status - information on whether the rule was applied correctly on the computer.

  • Action - determines whether traffic matching the rule conditions is allowed or blocked.

  • Profile - the Windows network profile or profiles for which the rule applies.

  • Local IP - the local address included in the rule.

  • Protocol - the communication protocol, for example TCP or UDP.

  • Local port - the port to which the port rule applies.

  • Active - enables quick enabling or disabling of the rule's application by the firewall.

Adding a rule

1

Go to IT Management > Firewall.

2

Click Add rule.

Dodaj regułę
Add a rule.
3

Select the computers on which the rule is to be deployed.

Wybierz komputery
Select computers
4

Select the traffic direction, action, and network profile.

5

Complete the rule name and optional description.

6

Select the rule type - for a program or for a port.

typ reguły
Rule type
7

Set whether the rule is to be active after deployment.

8

Click the button to save or create the rule.

Program rule configuration

Use a program rule when you want to control connections made by a specific application.

Depending on the selected option:

  • specify the path to the program executable file,

  • or select All programs, if the rule is to apply to every program on the computer that meets the remaining configuration conditions.

If the application can be installed in different locations, verify before deployment that the specified path is the same on all selected computers.

Port rule configuration

Use a port rule when you want to manage traffic on a specific local port.

  1. Select the rule type TCP/UDP port.

  2. Select protocol TCP or UDP.

  3. Specify whether the rule applies to all local ports or selected ports.

  4. If you select selected ports, enter the port number or port numbers required by the service in question.

  5. Save the rule.

For example, a rule for TCP port 443 can be used to control HTTPS communication if this matches the configuration of the given service.

Rule status

When creating a firewall rule, you can define whether after deployment it should be active, or inactive.

  • Active - the rule will be deployed to the specified computers and will be applied by the firewall immediately.

  • Inactive - the rule will also be deployed to the specified computers, but it will not be applied by the firewall.

Turning off the option Active does not cause the rule deployment to be skipped - it defines only its status.

The status of a deployed rule can later be changed from the rules table using the switch in the Active.

Informacja o utworzeniu oraz aktywacji reguły zapory.
Information about the creation and activation of the firewall rule.

Checking deployment

After saving the rule, check the Deployment status.

Status OK means that the rule was applied correctly on the given computer. Information about rule creation and activation is also displayed in notifications in the upper-right corner of the system.

Powiadomienia w prawym górnym rogu systemu
Notifications in the upper-right corner of the system.

Editing, copying, and deleting a rule

Actions are available for each rule to manage the configuration.

  • Editing - allows you to change the rule parameters or the list of assigned computers.

  • Copying - opens a copy of the existing rule with the same settings and assigned computers. You can change the parameters, assignments, or save a new rule without changes.

  • Deletion - removes the rule from the configuration.

  • Active - allows you to enable or disable the rule without deleting it.

Some rules may have a grayed-out edit icon. This means they are system-protected rules and cannot be modified from eAuditor Cloud.

FAQ

When will the rule appear on the computer?

The rule will be deployed when eAgent connects to the server and downloads the current configuration.

Will an inactive rule be deployed?

Yes. An inactive rule is delivered to the computer, but Microsoft Defender Firewall does not apply it until it is enabled.

How do I check whether the rule has been deployed?

Check the column Deployment status. Status OK confirms that the rule was applied correctly on the computer.

Can I change the computers assigned to an existing rule?

Yes. Open rule editing, change the list of assigned computers, and save the configuration.

What does the rule copy option do?

It creates a new configuration based on an existing rule, together with its settings and assigned computers. The original rule remains unchanged.

Why can't I edit some rules?

A grayed-out edit icon indicates a system-protected rule. Such a rule cannot be changed from eAuditor Cloud.

Last updated

Was this helpful?