Follow these steps to enable Firewall allowed or blocked traffic logging in managed systems.
Log on to ePO - On-prem as an administrator.
Go to Menu > Policy Catalog > Endpoint Security Firewall.
In the Endpoint Security Firewall page, click Policy Category > Options > My Default.
Click Show Advanced on the top left corner of the page.
In the Tuning Options section, enable these options:
Enable Log all allowed traffic
By Default, Log all blocked traffic is enabled. Save this policy.
Navigate to System Tree, and click on the Assigned Policies tab and in the Product section, select Endpoint Security Firewall.
Select Endpoint Security Firewall from the Product list, then click Edit Assignment.
In the next page, click Break inheritance and assign the policy > My Default > Assigned Policy and select the Save option.
In the System Tree page, select the system to assign the policy. Click Wake Up Agents, and select Force complete policy and task update and select OK.
Endpoint Security Firewall Policy by default gets enforced on the managed system.