Policy Configuration : Configuring Access Rules

Configuring App Control Advanced Global Settings
App Control is a licensed service, and you must also enable it to activate the functionality. The Firewall > App Control Advanced page provides the following global settings:
See the following sections:
Enabling App Control Globally
To globally enable App Control Advanced policies:
1
2
On the Policies tab, navigate to the Firewall > App Control Advanced page.
3
In the App Control Global Settings area, select Enable App Control to globally enable App Control.
App Control policies are applied to traffic within a network zone only if you enable the App Control Service for that zone. See Enabling App Control on Network Zones for a description of enabling App Control on a network zone.
4
Click Update. The Modify Task Description and Schedule window displays.
5
A description is automatically added in the Description field. Optionally change the description.
6
For Schedule, select one of the following radio buttons and set any associated fields:
Default – Use the default schedule configured for the Agent that manages this unit
Immediate – Enable App Control Advanced policies immediately
At – Select the exact time to enable App Control Advanced policies by using the pull-down lists for the hour, minute, time zone, month, and year. If your GMS deployment includes Agents in different time zones, you can select among them in the time zone pull-down list. Select the date from the calendar.
7
Click Accept to enable App Control Advanced policies on this schedule. Click Cancel to exit without saving the configuration.
Configuring an App Control Advanced Exclusion List
To configure a exclusion list for App Control Advanced policies:
1
2
On the Policies tab, navigate to the Firewall > App Control Advanced page.
3
In the App Control Global Settings area, click Configure App Control Settings to bring up the App Control Exclusion List window.
 
4
Select the Enable Application Control Exclusion List to activate the exclusion options in the window.
5
To use the IPS exclusion list, which can be configured from the Security Services > Intrusion Prevention page, and select Use IPS Exclusion List.
6
To use an address object for the exclusion list, select Use Application Control Exclusion Address Object, and then select an address object from the pull-down list.
 
7
Click OK. The Modify Task Description and Schedule window displays.
8
A description is automatically added in the Description field. Optionally change the description.
9
For Schedule, select one of the following radio buttons and set any associated fields:
Default – Use the default schedule configured for the Agent that manages this unit
Immediate – Enable the exclusion list immediately
At – Select the exact time to enable the exclusion list by using the pull-down lists for the hour, minute, time zone, month, and year. If your GMS deployment includes Agents in different time zones, you can select among them in the time zone pull-down list. Select the date from the calendar.
10
Click Accept to enable the exclusion list on this schedule. Click Cancel to exit without saving the configuration.
Synchronizing the Signature Database
To synchronize the signature database with MySonicWALL:
1
2
On the Policies tab, navigate to the Firewall > App Control Advanced page.
3
In the App Control Global Settings area, click Update App Control Signature Database. The Modify Task Description and Schedule window displays.
4
A description is automatically added in the Description field. Optionally change the description.
5
For Schedule, select one of the following radio buttons and set any associated fields:
Default – Use the default schedule configured for the Agent that manages this unit
Immediate – Synchronize the database immediately
At – Select the exact time to synchronize the database using the pull-down lists for the hour, minute, time zone, month, and year. If your GMS deployment includes Agents in different time zones, you can select among them in the time zone pull-down list. Select the date from the calendar.
6
Click Accept to synchronize the database on this schedule. Click Cancel to exit without saving the configuration.
Resetting App Control to Factory Defaults
To reset App Control settings and policy configuration to the factory default values for the selected unit or for all units in the selected group:
1
2
On the Policies tab, navigate to the Firewall > App Control Advanced page.
3
In the App Control Global Settings area, click Reset App Control Settings & Policies.
4
Click OK in the confirmation dialog box. The Modify Task Description and Schedule window displays.
5
A description is automatically added in the Description field. Optionally change the description.
6
For Schedule, select one of the following radio buttons and set any associated fields:
Default – Use the default schedule configured for the Agent that manages this unit
Immediate – Complete the reset immediately
At – Select the exact time to do the reset using the pull-down lists for the hour, minute, time zone, month, and year. If your GMS deployment includes Agents in different time zones, you can select among them in the time zone pull-down list. Select the date from the calendar.
7
Click Accept to complete the reset on this schedule. Click Cancel to exit without saving the configuration.