SonicOS 7.1 Security Services
- SonicOS 7.1
- About SonicOS
- Summary
- Configuring Content Filter
- Managing the SonicWall Gateway Anti-Virus Service
- SonicWall GAV Multi-Layered Approach
- SonicWall GAV Architecture
- Activating the Gateway Anti-Virus, Anti-Spyware, and Intrusion Prevention License
- Setting Up SonicWall Gateway Anti-Virus Protection
- Viewing SonicWall Gateway Anti-Virus Signatures
- Anti-Spyware Service
- Intrusion Prevention Service
- Configuring Geo-IP Filters
- Configuring Botnet Filters
- Configuring App Control
- About App Control Policy Creation
- Viewing App Control Status
- Enabling App Control
- Configuring App Control Global Settings
- Configuring App Control Advanced Settings
- Configuring App Control Advanced by Category
- Configuring App Control Advanced by Application
- Configuring App Control Advanced by Signature
- Viewing Signatures
- Viewing by All Categories and All Applications by Applications
- Viewing by All Categories and All Applications by Signatures
- Viewing by All Categories and All Applications by Category
- Viewing Just One Category
- Viewing Just One Application
- Displaying Details of Signature Applications
- Displaying Details of Application Signatures
- SonicWall Support
Configuring App Control
App Control is a licensed service and you must enable it to activate the functionality.
The POLICY | Security Services > App Control page provides a way to configure global App Control policies using categories, applications, and signatures. You can quickly enable blocking or logging for a whole category of applications, and can easily locate and do the same for an individual application or individual signature. When enabled, the category, application, or signature is blocked or logged globally without the need to create a policy on the POLICY | Rules and Policies > App Rules page. All application detection and prevention configuration is available on the POLICY | Rules and Policies > App Control page.
When Enable App Control is selected from the POLICY | Security Services > App Control | App Control Global Settings page, the dpi=1 Syslog tag is seen in the Connection Closed Syslog messages for all traffic that passed through Deep Packet Inspection. Traffic that did not pass through DPI shows dpi=0 in the Connection Closed Syslog messages. For more information about the Index of Syslog Tags Field Descriptions or Syslog examples showing the SPI tag, see the SonicOS Log Events Administration Guide.
You can configure the following settings on this page
- Select a category, an application, or a signature.
- Select blocking, logging, or both as the action.
- Specify users, groups, or IP address ranges to include in or exclude from the action.
- Set a schedule for enforcing the controls.
While these App Control settings are independent from App Rules policies, you can also create application match objects for any of the categories, applications, or signatures available here, and use those match objects in an App Rules policy. See About Application List Objects and Configuring Application List Objects for more information.
Informational videos with App Control configuration examples are available online at: https://www.sonicwall.com/support/video-tutorials.
- About App Control Policy Creation
- Viewing App Control Status
- About App Control Global Settings
- Configuring App Control Global Settings
- Viewing Signatures
- Configuring App Control by Category
- Configuring App Control by Application
- Configuring App Control by Signature
Was This Article Helpful?
Help us to improve our support portal