Kaspersky Embedded Systems Security 3.x

Configuring general settings of the Firewall Management task

October 25, 2023

ID 256070

To configure the general settings of the Firewall Management task using the Web Plug-in:

  1. In the main window of the Kaspersky Security Center Web Console, select DevicesPolicies & profiles.
  2. Click the policy name you want to configure.
  3. In the <Policy name> window that opens select the Application settings tab.
  4. Select the Network activity control section.
  5. Click the Settings button in the Firewall Management section.

    The Firewall Management window opens.

  6. On the General tab, in the Windows Firewall integration block, select the option for interaction between Kaspersky Embedded Systems Security for Windows and Windows Firewall:
    • Observe the state of Windows Firewall The program only observes the state of Windows Firewall. If this option is selected, the application only monitors the status of Windows Firewall and sends a warning event to Kaspersky Security Center if Windows Firewall is not started.

      If this option is selected to replace the Control the operation of Windows Firewall The program controls the operation of Windows Firewall according to the settings below option, the application restores the internal settings of Windows Firewall the next time the operating system of the protected device is started.

    • Control the operation of Windows Firewall The program controls the operation of Windows Firewall according to the settings below. If this option is selected, the application monitors Windows Firewall to the extent determined by the following settings:
      • Maintain the state of Windows Firewall.
      • Manage settings and rules of Windows Firewall.
      • Allow ICMP connections.
  7. In the Inbound connections block, configure the settings for incoming network connections:
    • Use the Action for inbound connections drop-down list to specify the action that Windows Firewall performs for all incoming network connections, unless otherwise defined in the Firewall rules for incoming connections.
    • If necessary, add Firewall rules for incoming connections.

      Firewall rules for incoming connections perform the role of exclusions. For example, if you configure an allowing rule for incoming network connections, and you select Block in the Action for inbound connections drop-down list, Windows Firewall allows incoming network connections that match the rule criteria.

  8. In the Outbound connections block, configure the settings for outgoing network connections:
    • Use the Action for outbound connections drop-down list to specify the action that Windows Firewall performs for all outgoing network connections, unless otherwise defined in the Firewall rules for outgoing connections.
    • If necessary, add Firewall rules for outgoing connections.

      Firewall rules for outgoing connections perform the role of exclusions. For example, if you configure a blocking rule for outgoing network connections, and select Allow in the Action for outbound connections drop-down list, Windows Firewall blocks outgoing network connections that match the rule criteria.

  9. Click the OK button to save the changes.

Kaspersky Embedded Systems Security for Windows applies the new settings to the running task. The date and time when the settings were changed are saved in the system audit log.

Setting

Description

Firewall rules for applications

You can manage application rules.

This type of rule allows targeted network connections for specified applications. The triggering criterion for these rules is based on a path to an executable file.

Firewall rules for ports

You can manage port rules.

This type of rule allows network connections for specified ports and protocols (TCP / UDP). The triggering criteria for these rules are based on the port number and protocol type.

Task management

You can configure settings to start the task on a schedule.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.