Application Rules |
To open Application rules window 1.Open Dr.Web menu , then select . 2.In the open window, click tile. 3.Make sure Dr.Web operates in administrator mode (the lock at the bottom of the program window is open ). Otherwise, click the lock . 4.Click the tile. A component parameters window opens. 5.In the section click . A window with a list of applications opens. For these applications, rules have been set. Figure 44. Application rules 6.To start creating a new rule set or editing an existing one, click or select an application and click . To search for a necessary rule, click . When an application is deleted from your computer, the related rules are not automatically deleted. You can delete them manually by clicking in the shortcut menu of the list. Editing of an existing rule set or creating a new rule set You can configure access to network resources as well as enable or disable launch of other applications in the (or <application name>) window. Figure 45. Creating a new rule set Launching other applications To enable or disable launch of other applications, from the drop-down list select one of the following: •—if you want to enable the application to run other processes. •—if you want to disable the application to run other processes. •—if you want to use the settings specified for the selected operation mode of Firewall. Access to network resources 1.Specify one of the following modes to access network resources: •—all connections are allowed. •—all connections are blocked. •—if you want to use the settings specified for the selected operation mode of Firewall. •—enables you to create a set of rules that allow or block different connections. 2.When you select the mode, a table with details on the application rule set displays below. Details
3.If necessary, edit the predefined rule set or create a new one. 4.If you select to create a new rule set or edit an existing one, adjust the settings in the open window. 5.When you finish adjusting the settings, click to save changes or to cancel them. When shifting to another mode, all changes made in the rule set will be kept. Enable the option if you want the access to network resources to be confirmed each time when the application is changed or updated. Creating application rules from the Firewall notification window When Firewall is operating in the interactive mode or in the Allow connections for trusted applications mode, you can start creating a new rule directly from the window with notification on an unknown connection attempt. Figure 46. Example of a notification on a network connection attempt
To add application rules 1.To make a decision, consider the following information displayed in the notification:
2.Once you make a decision, select an appropriate action: •To block application access using this port once, select . •To allow application access by this port once, select . •To open a window where you can create a new application filter rule, select . In the open window, you can either choose one of the predefined rules or create your rule for the application. 3.Click . Firewall executes the selected action and closes the notification window.
If a connection is initiated by a trusted application (an application with existing rules), but this application is run by an unknown parent process, Firewall displays the corresponding notification. To set parent process rules 1.Consider information about the parent process in the notification displayed on a connection attempt. 2.Once you make a decision about what action to perform, select one of the following: •To block this connection once, select . •To allow this connection, click . •To create a rule for the parent process, click and in the open window specify required settings. 3.Click . Firewall executes the selected action and closes the notification window. When an unknown process is run by another unknown process, a notification displays the corresponding details. If you click , a new window appears allowing you to create new rules for this application and its parent process. |