Firewall Management

January 20, 2022

ID 209531

During use on local area networks (LANs) and the Internet, a computer is exposed to viruses, other malware, and a variety of attacks that exploit vulnerabilities in operating systems and software.

The operating system firewall protects personal data that is stored on the user's computer. The firewall blocks most threats to the operating system when the computer is connected to the Internet or a LAN. Firewall Management detects all network connections of the user's computer and provides a list of IP addresses, as well as an indication of the status of the default network connection.

The Firewall Management component filters all network activity according to network packet rules. Configuring network packet rules lets you specify the desired level of computer protection, from blocking Internet access for all applications to allowing unlimited access.

While the Firewall Management task is running, Kaspersky Endpoint Security manages the parameters and rules of the operating system firewall. The application blocks any configuration of the operating system firewall parameters when, for example, a program or tool adds or deletes a rule. Kaspersky Endpoint Security checks the operating system firewall every 60 seconds and, if necessary, restores a set of the firewall rules. The checking period cannot be changed.

In Red Hat Enterprise Linux and CentOS 8 operating systems, firewall rules created by using Kaspersky Endpoint Security can be viewed only by means of Kaspersky Endpoint Security (kesl-control -F --query command).

Checking of the operating system firewall continues when the Firewall Management task is stopped. This allows the application to restore dynamic rules.

All outbound connections are allowed by default (default action setting), unless the corresponding blocking rules for the Firewall Management task are specified. The default action is performed with the lowest priority: if no other network packet rule has been triggered or if no network packet rules have been specified, the connection is allowed.

Before the Firewall Management task is enabled, we recommend that you disable other operating system firewall management tools.

Firewall Management settings

Setting

Description

Firewall Management enabled / disabled

This toggle button enables or disables Firewall Management.

This toggle button is switched off by default.

Network packet rules

Clicking the Configure network packet rules link opens the Network packet rules window. In this window, you can configure a list of network packet rules that are performed by the Firewall Management component when it detects the network connection attempt.

Available networks

Clicking the Configure available networks opens the Available networks window. In this window, you can you can configure a list of networks that the Firewall Management task will monitor.

Incoming connections

In this drop-down list, you can specify an action to be performed for incoming network connections:

  • Allow incoming network connections.
  • Block incoming network connections.

    The Allow action is selected by default.

Incoming packets

In this drop-down list you can specify an action to be performed for incoming packets:

  • Allow incoming packets.
  • Block incoming packets.

    The Allow action is selected by default.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.