Tune and tighten security by reviewing Firewall client rules and moving them to a Rules policy.
Firewall client rules are created manually on a client or automatically in Adaptive mode.
For information about server tasks, see the ePO - On-prem documentation.
From the System Tree, click Wake Up Agents.
The agent wake-up call collects the Firewall client properties, including client rules, from the client.
The Endpoint Security Firewall Property Translator task runs automatically every 15 minutes, scans the client properties for Firewall client rules, and adds them to the Firewall Client Rules page.
Important
Make sure in the ePO - On-prem server that the Endpoint Security Firewall Property Translator server task is left in a Disabled state. Enabling this task would run it in addition to the automatic execution mentioned above which may cause performance issues.
You can also manually run the client rule conversion as needed:
Select Menu → Automation → Server Tasks, then run the Endpoint Security Firewall Property Translator server task.
Select Menu → Reporting → Firewall Client Rules.
In the System Tree, select a group to display its details.
Review the client rules to determine which rules to promote to a Rules policy.
Move rules to a policy by selecting rules, clicking New Firewall Rule, then indicating the policy to move the rules to.
In the Firewall Options policy, deselect these options:
Enable Adaptive mode
Retain existing user-added rules and Adaptive mode rules when this policy is enforced
Enforce the updated Options and Rules policies.
The rules from the Rules policy replace the client rules that were created on the client system.