In the main window of the Web Console, select Devices → Policies & profiles.
Click the Add button.
The New policy window opens.
In the Select application section, select Kaspersky Embedded Systems Security for Windows and click Next.
On the General tab, you can perform the following actions:
Change the policy name.
The policy name cannot contain the following symbols: " * < : > ? \ | .
Select the policy status:
Active. After the next synchronization, the policy will be used as the active policy on the computer.
Inactive. Backup policy. If necessary, an inactive policy can be switched to active status.
Out-of-office. The policy is activated when a computer leaves the organization network perimeter.
Configure the inheritance of settings:
Inherit settings from parent policy. If this toggle button is switched on, the policy setting values are inherited from the top-level policy. Policy settings cannot be edited if is set for the parent policy.
Force inheritance of settings in child policies. If the toggle button is on, the values of the policy settings are propagated to the child policies. In the child policy settings the Inherit settings from parent policy check box is automatically selected. Child policy settings are inherited from the parent policy, except for the settings marked with . Child policy settings cannot be edited if is set for the parent policy.
On the Application settings tab, configure the policy settings as required.
Click the Save button.
The created policy appears in the list of policies on the Policies & profiles tab of the selected administration group. In the <Policy name> window, you can configure other settings, tasks and functions of Kaspersky Embedded Systems Security for Windows.
After a new policy is created, a set of allowing rules is created to prevent applications from being blocked, ensuring their uninterrupted operation. You can view the default rules in the task settings. See below for details and limitations.
By default, Kaspersky Embedded Systems Security for Windows creates a set of rules for inbound network traffic when creating a new policy:
Two allowing rules for the process of sharing the Windows desktop using Kaspersky Security Center Network Agent, which is located in the %Program Files% and %Program Files (x86)% folders. Status: enabled. Allowed external addresses: all. Protocols: TCP and UDP, one rule per protocol.
Two allowing rules for local port 15000. State: enabled. Allowed external addresses: all. Protocols: TCP and UDP, one rule per protocol.
By default, Kaspersky Embedded Systems Security for Windows creates a set of outgoing network traffic rules when creating a new policy:
Two allowing rules for the Kaspersky Embedded Systems Security for Windows service, which is located in the %Program Files% and %Program Files (x86)% folders. Status: enabled. Allowed external addresses: all. Protocols: TCP and UDP, one rule per protocol.
Two allowing rules for the worker process of Kaspersky Embedded Systems Security for Windows, which is located in the %Program Files% and %Program Files (x86)% folders. Status: enabled. Allowed external addresses: all. Protocols: TCP and UDP, one rule per protocol.
Two allowing rules for local port 13000. State: enabled. Allowed external addresses: all. Protocols: TCP and UDP, one rule per protocol.