SonicOS 7.0 Security Services Administration Guide

Configuring App Control Signatures by Application

Application-based configuration is the middle level of policy configuration on the POLICY | Rules and Policies > App Control | Signatures page, between the category-based and signature-based levels.

This configuration method allows you to create policy rules specific to a single application if you want to enforce the policy settings only on the signatures of this application without affecting other applications in the same category.

To configure an App Control policy for a specific application

  1. Navigate to the POLICY | Rules and Policies > App Control > Signatures page.
  2. Select an application from the Application drop-down menu (if you did not select a category, the category changes to that of the selected application). The Configure button to the right of the field is enabled as soon as an application is selected.

  3. Click Configure to display the App Control App Settings dialog for the selected application.

    If the application’s Block setting is set to Use Category Setting:
    To prevent the category settings from overriding your settings for the application, change the Block setting here to Enabled or Disabled, as desired, and update any other settings in this dialog to the specific values that you want.

    The fields at the top of the dialog, App Category and App Name, are not editable. The other settings default to the current settings of the category to which the application belongs. To retain this connection to the category settings for one or more fields, leave this selection in place for those fields.

  4. To block this application, select Enable in the Block drop-down menu.
  5. To create a log entry when this application is detected, select Enable in the Log drop-down menu.
  6. To target the selected block or log actions to a specific user or group of users, select a user group or individual user from the Included Users/Groups drop-down menu. Select All to apply the policy to all users.
  7. To exclude a specific user or group of users from the selected block or log actions, select a user group or user from the Excluded Users/Groups drop-down menu. Select None to apply the policy to all users.
  8. To target the selected block or log actions to a specific IP address or address range, select an Address Group or Address Object from the Included IP Address Range drop-down menu. Select All to apply the policy to all IP addresses.
  9. To exclude a specific IP address or address range from the selected block or log actions, select an Address Group or Address Object from the Excluded IP Address Range drop-down menu. Select None to apply the policy to all IP addresses.
  10. To enable this policy during specific days of the week and hours of the day, select one of the schedules from the Schedule drop-down menu. For a list of schedules, see Schedule Options in Configuring App Control Signatures by Category.
  11. By default, the Log Redundancy Filter has the Use Category Settings option selected; the field is dimmed and cannot be changed. To specify a different delay between log entries for repetitive events:

    1. Clear the Use Global Settings checkbox. The field becomes available.

    2. Enter the number of seconds for the delay into the Log Redundancy Filter field. The minimum number of seconds is 0 (no delay), the maximum is 999999, and the default is 0.

  12. Click OK.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden