background image

16

 

3..3 

XML Configuration files & ESET Configuration Editor

The ESET Configuration Editor is included with ESET Remote Administrator and can read configuration files 
exported by ESET Smart Security (for more information, see the ESET Remote Administrator manual). These 
configuration files also include rules and detailed configuration settings from the Personal firewall. The Personal 
firewall settings can be found in the Configuration Editor’s tree structure under 

ESET Smart Security, ESET NOD32 

Antivirus > Personal firewall > Setup

.

The most important attributes in the 

Personal firewall > Setup

 section are

 

Filtering mode

 and 

Rule setup

. These 

attributes allow you to specify rules, zones and other parameters. This dialog window looks almost the same as 
the one above, except for the option 

Discard previous settings on the target computer

. If this option enabled, 

all current rules on the target computer will be removed and replaced by those in ESET Remote Administrator. If 
disabled, original rules will not be deleted or modified by new rules.

Warning!

 

User-defined rules are identified by name. If the option 

Discard previous settings on the target 

computer

 is not enabled and an existing user-defined rule is renamed, a duplicate rule is created after the 

configuration is applied.

If you want to use an exported configuration but want to change Personal firewall settings only (and you do not 
wish to modify parameters of the real-time protection, email protection, update, etc.), the Configuration Editor 
offers the following methods:

1. 

Use the keyboard shortcut CTRL  + D to remove blue icons in other settings (the icons will revert to grey).

2. 

Navigate to 

ESET Smart Security, ESET NOD32 Antivirus > Personal firewall 

and press SPACEBAR (the 

 

icon of every setting in the Personal firewall section will change to blue).

3. 

Save the configuration by clicking 

File > Export selected to......

The difference between blue and grey icons is described in detail in the ESET Remote Administrator manual. 
Essentially, any changes you make to settings in the ESET Configuration Editor are marked by a blue icon–the 
resulting .xml file will contain only these settings. If you were to push out the .xml configuration created using the 
steps above, only the Personal firewall settings would be modified on client computers

3

.

3  Remember that there are several methods of installing a new .xml configuration: as part of a configuration task 

in ERA, as a configuration assigned to a remote install package, or by using the Import feature directly from the 

ESET Smart Security user interface.

Summary of Contents for PERSONAL FIREWALL

Page 1: ...ESET Personal Firewall we protect your digital worlds User Guide...

Page 2: ...Personal Firewall Copyright 2008 by ESET spol s r o ESET Personal Firewall was developed by ESET spol s r o For more information visit www eset com All rights reserved No part of this documentation m...

Page 3: ...re are several reasons A Personal firewall can eliminate attacks from within the local network e g an infected guest notebook connecting to the corporate network A Personal firewall allows the adminis...

Page 4: ...This mode is based on user defined rules as well as a basic set of predefined rules If a rule already exists to allow or deny a specific type of communication that rule is automatically applied For c...

Page 5: ...may wish to allow communication on port 443 HTTPS There are three ways to accomplish this o Wait until the web browser establishes communication on port 443 e g when you log in to your online banking...

Page 6: ...ve been defined the connection is denied and no dialog window is displayed This is the main difference between Interactive and Policy based mode Policy based mode is well suited to large corporate net...

Page 7: ...rewall will treat that network as not trusted Networks marked as Not trusted The opposite of the Trusted zone It should list all IP addresses address ranges and subnets that are automatically treated...

Page 8: ...add the IP addresses 217 67 22 98 and 72 32 7 91 and name it Internet FTP servers Create a new rule allowing outgoing FTP communication On the Remote tab add the zones Trusted zone and Internet FTP s...

Page 9: ...ication is enabled only for Outlook Express and HTTP traffic only for Mozilla Firefox 2 4 Rule configuration strategy in large networks If you wish to set the most strict level of network access for c...

Page 10: ...program settings based on an existing configuration In both cases the Zone and rule setup dialog windows are similar to each other Items with grey background mark rules defined by ESET In certain cas...

Page 11: ...e name of the application process to which the rule applies Remote port target communication port or group of ports Remote address target IP address or IP address range or subnet NOTE The rule order i...

Page 12: ...3 IMAP IP addresses of your email servers remote address can be filled in if you want very strict protection Web browsing Out TCP Web browser process 80 HTTP 443 HTTPS or proxy server port FTP client...

Page 13: ...ication Remote port Remote address svchost exe ven Out TCP svchost exe 443 update microsoft com download microsoftupdates com windowsupdate microsoft com 3 1 Detection of modified applications The App...

Page 14: ...and downloads PDF documents from the Internet Thus a specific rule exclusion would need to be defined to allow this activity 3 2 Logging network activity Information about processed or blocked activi...

Page 15: ...firewall can be viewed by clicking Protection status Personal firewall from the main program window You can right click to open a context menu showing additional options such as Temporarily deny comm...

Page 16: ...an existing user defined rule is renamed a duplicate rule is created after the configuration is applied If you want to use an exported configuration but want to change Personal firewall settings only...

Page 17: ...ss of the filtering mode This will prevent users from seeing dialog windows asking them to add the current subnet to the Trusted or Not trusted zone ESET Smart Security does not contain any predefined...

Reviews: