Creating a network packet rule

You can create a network packet rule in the following ways:

When creating network packet rules, remember that they have priority over network rules for applications.

How to use the Network Monitor tool to create a network packet rule in the application interface

How to use Firewall settings to create a network packet rule in the application interface

How to create a network packet rule in the Administration Console (MMC)

How to create a network packet rule in the Web Console and Cloud Console

Network packet rule settings

Parameter

Description

Action

Allow.

Block.

By application rules. If this option is selected, Firewall applies the application network rules to the network connection.

Protocol

Control network activity over the selected protocol: TCP, UDP, ICMP, ICMPv6, IGMP and GRE.

If ICMP or ICMPv6 is selected as the protocol, you can define the ICMP packet type and code.

If TCP or UDP is selected as the protocol type, you can specify the comma-delimited port numbers of the local and remote computers between which the connection is to be monitored.

Direction

Inbound (packet). Firewall applies the network rule to all inbound network packets.

Inbound. Firewall applies the network rule to all network packets sent via a connection that was initiated by a remote computer.

Inbound / Outbound. Firewall applies the network rule to both inbound and outbound network packets, regardless of whether the user's computer or a remote computer initiated the network connection.

Outbound (packet). Firewall applies the network rule to all outbound network packets.

Outbound. Firewall applies the network rule to all network packets sent via a connection that was initiated by the user's computer.

The TCP protocol establishes a connection. Use the Inbound, Outbound and Inbound/Outbound directions for TCP. All other protocols do not establish connections, but they send packets. For all other protocols, use the Inbound (packet), Outbound (packets) or Inbound/Outbound directions.

Network adapters

Network adapters that can send and/or receive network packets. Specifying the settings of network adapters makes it possible to differentiate between network packets sent or received by network adapters with identical IP addresses.

Time to live (TTL)

Restrict control of network packets based on their time to live (TTL).

Remote addresses

Network addresses of remote computers that can send and receive network packets. Firewall applies the network rule to the specified range of remote network addresses. You can include all IP addresses into a network rule, create a separate list of IP addresses, or select a subnetwork (Trusted networks, Local networks, Public networks).

Local addresses

Network addresses of computers that can send and receive network packets. Firewall applies a network rule to the specified range of local network addresses. You can include all IP addresses in a network rule or create a separate list of IP addresses.

Sometimes the local address cannot be obtained for applications. If this is the case, this parameter is ignored.

Page top