Creating a firewall policy
The Symantec Endpoint Protection Small Business Edition includes a default
Firewall policy with default firewall rules for the office environment. The office
environment is normally under the protection of corporate firewalls, boundary
packet filters, or antivirus servers. Therefore, it is normally more secure than
most home environments, where limited boundary protection is available.
When you install the console for the first time, it adds a default Firewall policy
to each group automatically.
When you enable firewall protection, the policy allows all inbound IP-based
network traffic and all outbound IP-based network traffic, with the following
exceptions:
■
The default firewall protection blocks inbound and outbound IPv6 traffic with
all remote systems.
Note:
IPv6 is a network layer protocol that is used on the Internet. If you install
the client on the computers that run Microsoft Vista, the Rules list includes
several default rules that block the Ethernet protocol type of IPv6. If you
remove the default rules, you must create a rule that blocks IPv6.
■
The default firewall protection restricts the inbound connections for a few
protocols that are often used in attacks (for example, Windows file sharing).
Internal network connections are allowed and external networks are blocked.
Table 15-3
describes the tasks that you can perform to configure a new firewall
policy. You must add a firewall policy first, but thereafter, the remaining tasks
are optional and you can complete them in any order.
Table 15-3
How to create a firewall policy
Description
Task
When you create a new policy, you give it a name and a
description. You also specify the groups to which the policy is
applied.
A firewall policy is automatically enabled when you create it.
But you can disable if you need to.
See
“Enabling and disabling a firewall policy”
on page 210.
Add a firewall policy
209
Managing firewall protection
Creating a firewall policy
Summary of Contents for 20032623 - Endpoint Protection Small Business Edition
Page 1: ...Symantec Endpoint Protection Small Business Edition Implementation Guide...
Page 3: ...Symantec Corporation 350 Ellis Street Mountain View CA 94043 http www symantec com...
Page 34: ...34...
Page 54: ...Installing Symantec Endpoint Protection Manager What you can do from the console 54...
Page 70: ...Managing product licenses Licensing an unmanaged client 70...
Page 74: ...Preparing for client installation Preparing Windows operating systems for remote deployment 74...
Page 204: ...Managing Tamper Protection Changing Tamper Protection settings 204...
Page 236: ...Managing intrusion prevention Creating exceptions for IPS signatures 236...
Page 303: ...Maintaining your security environment Chapter 22 Preparing for disaster recovery 3 Section...
Page 304: ...304...
Page 308: ...Preparing for disaster recovery Backing up the database and logs 308...
Page 310: ...310...