Create Firewall timed groups to restrict Internet access until a client system connects over a VPN.
Select Menu → Policy → Policy Catalog, then select Endpoint Security Firewall from the Product list.
From the Category list, select Rules.
Click the name of an editable policy.
Create a Firewall group with default settings that allow Internet connectivity.
In the Schedule section, select how to enable the group.
Create a connection isolation group that matches the VPN network to allow needed traffic.
Tip
Best Practice: To allow outbound traffic from only the connection isolation group on the client system, don't place any Firewall rules below this group.
Click Save.