Configuring App Control Global Settings

The Firewall > App Control Advanced page provides the following global settings:

Topics:

Enabling App Control

To enable App Control and configure the global settings:
1
2
3
Click the Configure icon for the desired zone. The Edit Zone dialog displays.

4
Select the Enable App Control Service checkbox. This option is not selected by default.
5

The Network > Zones page displays a green indicator in the App Control column for any zones that have the App Control service enabled.

6
7
Click the Configure App Control Settings button. The App Control Exclusion List dialog displays.

8
Select the Enable Application Control Exclusion List checkbox. This option is not selected by default.
9
The IPS exclusion list, which can be configured from the Security Services > Intrusion Prevention page, select the Use IPS Exclusion List radio button. This is the default.
To use an address object for the exclusion list, select the Use Application Control Exclusion Address Object radio button, and then select an address object from the drop-down menu.

10

Resetting App Control to Factory Default

To reset App Control settings and policy configuration to the factory default values:
1
Click the Reset App Control Settings & Policies button on the Firewall > App Control Advanced page.
2
Click OK in the confirmation dialog.

Configuring Logging and Log Filter Interval

To enable logging for all apps and specify a redundancy filter interval:
1
In the App Control Global Settings section of the Firewall > App Control Advanced page, select the Enable Logging For All Apps checkbox.
2
Click the Accept button.

Configuring Application Control by Category

Category-based configuration is the most broadly based method of policy configuration on the Firewall > App Control Advanced page. The Category drop-down menu lists available categories.

To configure an App Control policy for an application category:
1
Navigate to the Firewall > App Control Advanced page.
2
Under App Control Advanced, select an application category from the Category drop-down menu. A Configure icon appears to the right of the field as soon as a category is selected.
3
Click the Configure icon. The App Control Category Settings dialog displays the selected category.

4
To block applications in this category, select Enable in the Block drop-down menu. The default is Disable.
5
6
7
8
To target the selected block or log actions to a specific IP address or address range, select an Address Group or Address Object from the Included IP Address Range drop-down menu. Select All to apply the policy to all IP addresses.
9
To exclude a specific IP address or address range from the selected block or log actions, select an Address Group or Address Object from the Excluded IP Address Range drop-down menu. Select None to apply the policy to all IP addresses.
10
 

This schedule

Enables the policy

Always on

At all times.

Work Hours

Monday through Friday, 8:00 AM to 5:00 PM.

M-T-W-T-F 08:00 to 17:00

Monday through Friday, 8:00 AM to 5:00 PM.

After Hours

Monday through Friday, 5:00 PM to 8:00 AM.

M-T-W-T-F 00:00 to 08:00

Monday through Friday, midnight to 8:00 AM.

M-T-W-T-F 17:00 to 24:00

Monday through Friday, 5:00 PM to midnight.

SU-S 00:00 to 24:00

At all times (Sunday through Saturday, 24 hours a day).

Weekend Hours

Friday at 5:00 PM through Monday at 8:00 AM.

11
12

Configuring Application Control by Application

Application based configuration is the middle level of policy configuration on the Firewall > App Control Advanced page, between the category based and signature based levels.

This configuration method allows you to create policy rules specific to a single application if you want to enforce the policy settings only on the signatures of this application without affecting other applications in the same category.

To configure an App Control policy for a specific application:
1
Navigate to the Firewall > App Control Advanced page.
2
Under App Control Advanced, first select a category from the Category drop-down menu.
3
Next, select an application in this category from the Application drop-down menu. A Configure icon appears to the right of the field as soon as an application is selected.

4
Click the Configure icon to display the App Control App Settings dialog for the selected application.

The dimmed App Category and App Name fields at the top of the dialog are not editable. The application configuration parameters default to the current settings of the category to which the application belongs.

5
Enable to block this application
Disable to unblock it.
6
Enable to create log entries
Disable to not create log entries
7
All to apply the policy to all users.
8
None to apply the policy to all users.
9
All to apply the policy to all IP addresses.
10
None to apply the policy to all IP addresses.
11
 

This schedule

Enables the policy

Always on

At all times.

Work Hours

Monday through Friday, 8:00 AM to 5:00 PM.

M-T-W-T-F 08:00 to 17:00

Monday through Friday, 8:00 AM to 5:00 PM.

After Hours

Monday through Friday, 5:00 PM to 8:00 AM.

M-T-W-T-F 00:00 to 08:00

Monday through Friday, midnight to 8:00 AM.

M-T-W-T-F 17:00 to 24:00

Monday through Friday, 5:00 PM to midnight.

SU-S 00:00 to 24:00

At all times (Sunday through Saturday, 24 hours a day).

Weekend Hours

Friday at 5:00 PM through Monday at 8:00 AM.

12
By default, the Log Redundancy Filter (seconds) checkbox is selected, and the specific application uses the Category settings. The Log Redundancy Filter field is dimmed. To specify a different delay between log entries for repetitive events for this particular application:
a
Deselect the Log Redundancy Filter checkbox. The Log Redundancy Filter field becomes available.
b
13

Configuring Application Control by Signature

Signature based configuration is the lowest, most specific, level of policy configuration on the Firewall > App Control Advanced page.

Setting a policy based on a specific signature allows you to configure policy settings for the individual signature without influence on other signatures of the same application.

To configure an App Control policy for a specific signature:
1
Navigate to the Firewall > App Control Advanced page.
2
Under App Control Advanced, first select a category from the Category drop-down menu.
3
4
To display the specific signatures for this application, select Signature in the Viewed by drop-down menu. The Freestyle gaming application has two signatures.
5
Click the Configure icon in the row for the signature you want to work with. The App Control Signature Settings dialog displays.
TIP: You also can display the Edit App Control Signature dialog by entering the signature ID in the Lookup Signature ID field and then clicking the Edit icon.

TIP: To modify the settings for the application, click the Edit icon by the Application ID field to display the Edit App Control App dialog. For information about the Edit App Control App dialog, see Configuring Application Control by Application .

The dimmed fields at the top of the dialog are not editable and display identifying values by which this signature can be detected:

 

The default policy settings for the signature are set to the current settings for the application to which the signature belongs.

6
Enable to block this application
Disable to unblock it.
7
Enable to create log entries
Disable to not create log entries
8
All to apply the policy to all users.
9
None to apply the policy to all users.
10
All to apply the policy to all IP addresses.
11
None to apply the policy to all IP addresses.
12
 

This schedule

Enables the policy

Always on

At all times.

Work Hours

Monday through Friday, 8:00 AM to 5:00 PM.

M-T-W-T-F 08:00 to 17:00

Monday through Friday, 8:00 AM to 5:00 PM.

After Hours

Monday through Friday, 5:00 PM to 8:00 AM.

M-T-W-T-F 00:00 to 08:00

Monday through Friday, midnight to 8:00 AM.

M-T-W-T-F 17:00 to 24:00

Monday through Friday, 5:00 PM to midnight.

SU-S 00:00 to 24:00

At all times (Sunday through Saturday, 24 hours a day).

Weekend Hours

Friday at 5:00 PM through Monday at 8:00 AM.

13
By default, the Log Redundancy Filter (seconds) checkbox is selected, and the specific application uses the Category settings. The Log Redundancy Filter field is dimmed. To specify a different delay between log entries for repetitive events for this particular application:
a
Deselect the Log Redundancy Filter checkbox. The Log Redundancy Filter field becomes available.
b
14
To see detailed information about the signature, click here in the Note at the bottom of the dialog.
15