- Go to Devices.
- Select a desktop or server group.
- Click Configure Policy.
Click the image to enlarge.
- Click Firewall > In Office or Out of Office.
- Select Enable Firewall > Advanced Mode.
Click the image to enlarge.
- To add an exception:
- Click Add.
- Type the name for the exception.
- Next to Action, click one of the following:
- Allow all network traffic
- Deny all network traffic
- Next to Direction, click Inbound or Outbound to select the type of traffic to which to apply the exception settings.
- Select the type of network protocol from the Protocol list:
- All
- TCP/UDP (default)
- TCP
- UDP
- ICMP
- ICMPv6
- Click one of the following to specify client ports:
- All ports (default)
- Range: type a range of ports
- Specified ports: specify individual ports. Use a comma "," to separate port numbers.
- Under Machines, select client IP addresses to include in the exception. For example, if you select Deny all network traffic (Inbound and Outbound) and type the IP address for a client on the network, then any client that has this exception in its policy will not be able to send or receive data to or from that IP address. Click one of the following:
- All IP addresses (default)
- Single IP: Type an IPv4 or IPv6 address, or a host name. To resolve the client host name to an IP address, click Resolve.
- IP range (for IPv4 or IPv6): Type either two IPv4 or two IPv6 addresses in the From and To fields. It is not possible to type an IPv6 address in one field and an IPv4 address in the other field.
- IP range (for IPv6): Type an IPv6 address prefix and length.
- Click Save.
Click the image to enlarge.
- To edit an exception, click Edit and then modify the settings in the screen that displays.
- To move an exception up or down the list, select the exception and then click Move Up or Move Down until it is in your preferred position.
- To remove an exception, select the exception and then click Remove.
- Go to the Configure Policy screen by performing one of the following:
- Click the Windows icon.
- Go to Firewall.
- Select Advanced Mode.
Click the image to enlarge.
- Go to the Exception List section.
Click the image to enlarge.
- To add an exception:
- Click Add.
- Type the name for the exception.
- Select the action to take on network traffics that meet the exception criteria.
- Select the traffic direction to apply the exception settings.
- Select the type of network protocol to apply the exception settings.
- Specify the endpoint ports to take the action.
- Specify the endpoint IP addresses to include in the exception.
For example, if you choose to deny all inbound and outbound network traffic and specify the IP address for a single endpoint on the network, then any endpoint that applies this exception setting cannot send or receive data to or from that IP address.- All IP addresses
- Single IP: Type an IPv4 or IPv6 address.
- IP range: Type an IPv4 or IPv6 address range.
- Click OK.
Click the image to enlarge.
- To view or edit an exception, click a name in the exception list.
- To reorder the exception list, drag an exception to a different row.
- To delete an exception, point to the exception and click the Trash bin icon in the last column of the list.