SonicOS 7.0 Security Services Administration Guide
- SonicOS 7.0
- Summary
- Managing the SonicWall Gateway Anti-Virus Service
- SonicWall GAV Multi-Layered Approach
- SonicWall GAV Architecture
- Activating the Gateway Anti-Virus, Anti-Spyware, and Intrusion Prevention License
- Setting Up SonicWall Gateway Anti-Virus Protection
- Viewing SonicWall Gateway Anti-Virus Signatures
- Anti-Spyware Service
- Intrusion Prevention Service
- Configuring Geo-IP Filters
- Configuring Botnet Filters
- Configuring App Control
- About App Control Policy Creation
- Viewing App Control Status
- Configuring App Control Global Settings
- Configuring App Control Signatures
- Configuring App Control Signatures by Category
- Configuring App Control Signatures by Application
- Configuring App Control Advanced by Signature
- Viewing Signatures
- Viewing by All Categories and All Applications by Applications
- Viewing by All Categories and All Applications by Signatures
- Viewing by All Categories and All Applications by Category
- Viewing Just One Category
- Viewing Just One Application
- Displaying Details of Signature Applications
- Displaying Details of Application Signatures
- Configuring Content Filter
- SonicWall Support
Configuring App Control Signatures by Category
Category-based configuration is the most broadly based method of policy configuration on the POLICY | Rules and Policies > App Control > Signatures page. The list of categories is available in the Category drop-down menu.
To configure an App Control policy for an application category
- Navigate to the POLICY | Rules and Policies > App Control > Signatures page.
- Select an application category from the Category drop-down menu. The Configure icon to the right of the field is enabled as soon as a category is selected.
-
Click Configure to display the App Control Category Settings dialog for the selected category.
- To block applications in this category, select Enable in the Block drop-down menu.
- To create a log entry when applications in this category are detected, select Enable in the Log drop-down menu.
- To target the selected block or log actions to a specific user or group of users, select a user group or individual user from the Included Users/Groups drop-down menu. Select All to apply the policy to all users.
- To exclude a specific user or group of users from the selected block or log actions, select a user group or individual user from the Excluded Users/Groups drop-down menu. Select None to apply the policy to all users.
- To target the selected block or log actions to a specific IP address or address range, select an Address Group or Address Object from the Included IP Address Range drop-down menu. Select All to apply the policy to all IP addresses.
- To exclude a specific IP address or address range from the selected block or log actions, select an Address Group or Address Object from the Excluded IP Address Range drop-down menu. Select None to apply the policy to all IP addresses.
-
To enable this policy during specific days of the week and hours of the day, select one of the following schedules from the Schedule drop-down menu:
Schedule Options This schedule Enables the policy Always on At all times. This option is selected by default. Work Hours Monday through Friday, 8:00 AM to 5:00 PM. M-T-W-T-F 08:00 to 17:00 Monday through Friday, 8:00 AM to 5:00 PM (same as Work Hours). After Hours Monday through Friday, 5:00 PM to 8:00 AM. M-T-W-T-F 00:00 to 08:00 Monday through Friday, midnight to 8:00 AM. M-T-W-T-F 17:00 to 24:00 Monday through Friday, 5:00 PM to midnight. SU-S 00:00 to 24:00 24 hours a day, Sunday through Saturday (same as Always On). Weekend Hours Friday at 5:00 PM through Monday at 8:00 AM. AppFlow Report Hours During the time configured for AppFlow reports. SU-M-T-W-TH-F-S 00:00 to 24:00 24 hours a day, Sunday through Saturday (same as Always On).
TSR Report Hours During the time configured for TSR reports. -
By default, the Use Global Settings option is selected and has a default of 60 seconds, which cannot be changed (the field is dimmed). To specify a different delay between log entries for repetitive events:
- Deselect the Use Global Settings checkbox. The field becomes available.
- Enter the number of seconds for the delay into the Log Redundancy Filter field. The minimum number of seconds is 0 (no delay), the maximum is 999999, and the default is 0.
- Click OK.
Was This Article Helpful?
Help us to improve our support portal