Here are answers to frequently asked questions.
Adaptive mode is a setting that you can apply to Firewall when testing new rollouts. This mode enables the client system to automatically create rules that allow activity while preserving minimum protection against vulnerabilities. The following questions and answers can help you use this feature.
How do you turn on Adaptive mode?
Enable this option in the Firewall Options settings.
Enable this option in the Firewall Options settings and apply this policy to the client.
How does Adaptive mode work with Firewall?
Adaptive mode creates rules on the client system that allow network packets not covered by existing firewall rules. Firewall client rules are created on a per-process basis. The processes associated with firewall client rules are based on path, file description, digital signature, and MD5 hash.
When is a rule not created automatically with Adaptive mode?
There is no application associated with the packet when examined in the client activity log. Some of the most common examples include:
Incoming requests for services that aren't running, such as FTP or telnet
Incoming ICMP, such as an echo request
Incoming or outgoing ICMP on Windows Vista
TCP packets to port 139 (NetBIOS SSN) or 445 (MSDS), which might be required for Windows file sharing
IPsec packets associated with VPN client solutions
There is already a rule that blocks or allows the packet.
The applied Rules policy has a location-aware group with connection isolation enabled and the following is true:
An active NIC matches the group.
The packet is sent or received on a NIC that doesn't match the group.
The packet isn't TCP, UDP, or ICMP.
More than one user is logged on to the system, or no user is logged on to the system.