SonicOS 7.0 Rules and Policies for Classic Mode
- SonicOS 7.0 Rules and Policies
- Access Rules
- Setting Firewall Access Rules
- About Connection Limiting
- Using Bandwidth Management with Access Rules
- Creating Access Rules
- Configuring Access Rules for IPv6
- Enabling and Disabling Access Rules
- Editing Access Rules
- Deleting Access Rules
- Restoring Access Rules to Default Settings
- Displaying Access Rules
- Displaying Access Rule Traffic Statistics
- Configuring Access Rules for NAT64
- Configuring Access Rules for a Zone
- Access Rules for DNS Proxy
- User Priority for Access Rules
- Access Rule Configuration Examples
- Setting Firewall Access Rules
- NAT Rules
- About NAT in SonicOS
- About NAT Load Balancing
- About NAT64
- About FQDN-based NAT
- About Source MAC Address Override
- Viewing NAT Policy Entries
- Adding or Editing NAT or NAT64 Rule Policies
- Deleting NAT Policies
- Creating NAT Rule Policies: Examples
- Creating a One-to-One NAT Policy for Inbound Traffic
- Creating a One-to-One NAT Policy for Outbound Traffic
- Inbound Port Address Translation via One-to-One NAT Policy
- Inbound Port Address Translation via WAN IP Address
- Creating a Many-to-One NAT Policy
- Creating a Many-to-Many NAT Policy
- Creating a One-to-Many NAT Load Balancing Policy
- Creating a NAT Load Balancing Policy for Two Web Servers
- Creating a WAN-to-WAN Access Rule for a NAT64 Policy
- DNS Doctoring
- Routing
- Content Filter Rules
- App Rules
- About App Rules
- Rules and Policies > App Rules
- Verifying App Rules Configuration
- App Rules Use Cases
- Creating a Regular Expression in a Match Object
- Policy-based Application Rules
- Logging Application Signature-based Policies
- Compliance Enforcement
- Server Protection
- Hosted Email Environments
- Email Control
- Web Browser Control
- HTTP Post Control
- Forbidden File Type Control
- ActiveX Control
- FTP Control
- Bandwidth Management
- Bypass DPI
- Custom Signature
- Reverse Shell Exploit Prevention
- Endpoint Rules
- SonicWall Support
Rules and Policies > App Rules
You must enable application control before you can use App Rules policies, although you can create policies without enabling the feature. Application control is enabled with a global setting, and must also be enabled on each network zone that you want to control.
For any of the listed access rules, when the Enabled checkbox is selected from the POLICY | Rules and Policies > Access Rules page, then the dpi=1 Syslog tag is seen in Connection Closed Syslog messages for all traffic that passed through Deep Packet Inspection. Traffic that did not pass through DPI shows dpi=0 in the Connection Closed Syslog messages. For more information about the Index of Syslog Tags Field Descriptions and Syslog examples showing the SPI tag, see the SonicOS Log Events Administration Guide.
You can configure application control policies by using the App Rule wizard or manually on the POLICY | Rules and Policies > App Rules page. The wizard provides a safe method of configuration and helps prevent errors that could result in unnecessary blocking of network traffic. Manual configuration offers more flexibility for situations that require custom actions or policies.
App Rules policies require a match object (or application list object) and an action object. You can configure match objects on the OBJECT | Match Objects > Match Objects pages. You also configure application list objects on the OBJECT | Match Objects > Match Objectspages. When creating an application list object, you choose from the same application categories, signatures, or specific applications that are shown on the POLICY | Security Services > App Control page. Action objects are created on the OBJECT | Action Objects pages.
By comparison, you can configure application control global blocking or logging settings on the POLICY | Rules and Policies > App Control > App Rule Actions page. No match objects or action objects are required.
For information about configuring App Rules policies and the objects used in them, see the following topics:
Was This Article Helpful?
Help us to improve our support portal