Configuring general settings of the Firewall Management task
To configure the general settings of the Firewall Management task using the Web Plug-in:
In the main window of the Kaspersky Security Center Web Console, select Devices → Policies & profiles.
Click the policy name you want to configure.
In the <Policy name> window that opens select the Application settings tab.
Select the Network activity control section.
Click the Settings button in the Firewall Management section.
The Firewall Management window opens.
On the General tab, in the Windows Firewall integration block, select the option for interaction between Kaspersky Industrial CyberSecurity for Nodes and Windows Firewall:
Observe the state of Windows Firewall The program only observes the state of Windows Firewall. If this option is selected, the application only monitors the status of Windows Firewall and sends a warning event to Kaspersky Security Center if Windows Firewall is not started.
If this option is selected to replace the Control the operation of Windows Firewall The program controls the operation of Windows Firewall according to the settings below option, the application restores the internal settings of Windows Firewall the next time the operating system of the protected device is started.
Control the operation of Windows Firewall The program controls the operation of Windows Firewall according to the settings below. If this option is selected, the application monitors Windows Firewall to the extent determined by the following settings:
This feature enables or disables management of Windows Firewall settings and rules.
If the function is enabled, the application performs the following actions:
Polls Windows Firewall at an interval of one minute.
Reads and copies Windows Firewall settings, including firewall rules.
Sets the values of Windows Firewall settings to match the Firewall Management task settings.
Creates a list of Kaspersky Security Group firewall rules in the Windows Firewall snap-in. This set contains all firewall rules of the Firewall Management task.
Later, when polling Windows Firewall, the application does not synchronize the list of Kaspersky Security Group firewall rules with the list of rules of the Firewall Management task. To synchronize the lists of firewall rules, you must restart the Firewall Management task.
Restricts the ability to edit Windows Firewall settings and rules using third-party tools or directly in the snap-in (wf.msc). If Windows Firewall settings or rules are changed, within one minute the application rolls back the changes to the settings values defined using the Firewall Management task.
If the function is disabled, the application restores the Windows Firewall settings and rules to the values that the application saved after the first poll of Windows Firewall and no longer manages the Windows Firewall settings and rules.
This feature cannot be disabled if the Maintain the state of Windows Firewall feature is disabled.
The function allows or blocks incoming and outgoing network connections via the ICMPv4 and ICMPv6 protocols.
If this function is enabled, Windows Firewall allows incoming and outgoing network connections via the ICMPv4 and ICMPv6 protocols, regardless of the task settings for incoming and outgoing connections.
On operating systems below Windows 7, Windows Firewall allows only incoming network connections via the ICMPv4 and ICMPv6 protocols.
This function is disabled by default.
In the Inbound connections block, configure the settings for incoming network connections:
Use the Action for inbound connections drop-down list to specify the action that Windows Firewall performs for all incoming network connections, unless otherwise defined in the Firewall rules for incoming connections.
Firewall rules for incoming connections perform the role of exclusions. For example, if you configure an allowing rule for incoming network connections, and you select Block in the Action for inbound connections drop-down list, Windows Firewall allows incoming network connections that match the rule criteria.
In the Outbound connections block, configure the settings for outgoing network connections:
Use the Action for outbound connections drop-down list to specify the action that Windows Firewall performs for all outgoing network connections, unless otherwise defined in the Firewall rules for outgoing connections.
Firewall rules for outgoing connections perform the role of exclusions. For example, if you configure a blocking rule for outgoing network connections, and select Allow in the Action for outbound connections drop-down list, Windows Firewall blocks outgoing network connections that match the rule criteria.
Click the OK button to save the changes.
Kaspersky Industrial CyberSecurity for Nodes applies the new settings to the running task. The date and time when the settings were changed are saved in the system audit log.
Setting
Description
Firewall rules for applications
You can manage application rules.
This type of rule allows targeted network connections for specified applications. The triggering criterion for these rules is based on a path to an executable file.
Firewall rules for ports
You can manage port rules.
This type of rule allows network connections for specified ports and protocols (TCP / UDP). The triggering criteria for these rules are based on the port number and protocol type.
Task management
You can configure settings to start the task on a schedule.