I disabled the fast boot. I really saw the initialization window with ESET logo. Now it sometimes appears, sometimes not, but the firewall is fully working both after shutdown the computer and after rebooting. Then I turned on Interactive mode and here are my rules.
Firewall rules
Name Protocol Direction Local Remote
Ask traffic for openvpn.exe TCP and UDP In
Deny incoming connections Any In
Allow traffic for ProtonVPN.exe TCP and UDP Out
Allow traffic for ProtonVPNService.exe TCP and UDP Out
Ask traffic for firefox.exe TCP and UDP Out
Ask traffic for tor.exe TCP and UDP Out
Allow traffic for egui.exe TCP and UDP Out
Allow traffic for ekrn.exe/ekrn TCP and UDP Out
Allow traffic for dnscrypt-proxy.exe TCP and UDP Out
Allow traffic for svchost.exe/Dnscache TCP and UDP Out
Allow traffic for svchost.exe/Dhcp TCP and UDP Out
Deny outgoing connections Any Out
Deny traffic for svchost.exe/CryptSvc TCP and UDP Out
Deny outgoing multicast DNS requests UDP Out IP: 224.0.0.252
Port: 5355
Deny outgoing NETBIOS requests TCP and UDP Out Port: 445,137-139
Deny outgoing LDAP requests TCP and UDP Out Port: 389,3268,49152-49159
But... There is still a leakage of traffic, which is forbidden not only in the firewall rules, but in the system. These are NetBIOS, mDNS, SSDP, UDP. It seems to be ekrn.exe file. So it is a component of ESET Internet Security. It connects to various not Eset IP addresses (224.0.0.22, 192.168.0.1, 192.168.0.100, 65.52.98.233, etc.) using NetBIOS protocol. But is it normal behavior?