4.3. Process Actions

In the Network Status section of the firewall administration interface, the following actions can be taken for a selected process:

Create a rule based on the selected process

With reference to the current state of the network communication of a particular process, a network security rule allowing/dropping traffic for a particular process and network service in a corresponding direction can be created. This is a simple way how to create a rule without demanding and time-consuming copying of all necessary parameters into a dialog where rules are created.

The new rule is added to the list of rules (before the default rule) in the Network Policy section. It can be moved within the list and modified if desirable (for details, see chapter 5. Network Policy).

Display rules relevant to the selected process

A special dialog window can be opened to view a list of network security rules related to the particular process. This feature provides users with various information issues, such as which rule enables/disables the particular network traffic, etc.

Note: In the list of rules related to a particular process, it is not possible to modify or move rules. However, these actions can be performed in the Network Policy section.

Show connections related to the selected process

If at least one network connection of a particular process is active, a list of these connection can be viewed in a special dialog window. Key parameters, such as remote IP address, traffic direction, transfer protocol, ports and volume of transmitted data, are provided for each connection.

List of network connections also provides important information on clients connecting to a particular service. Great volume of connections from one client or an extremely great volume of data transmitted can point at an attack.