Jump to content

Firewall Rules Specifying Services


Recommended Posts

Hello,

The ESET Server Security online documentation doesn't have detailed information on configuring firewall rules (the only thing it has is https://help.eset.com/efsw/11.0/en-US/idh_dialog_epfw_app_tree_rules_page.html), and the closest thing I can find is https://help.eset.com/ees/11/en-US/idh_dialog_epfw_rule_create_general.html (but this is for ESET Endpoint Security).  This seems to indicate that we should be able to specify a Service rather than an application path:

Service—You can select a system service instead of application. Open the drop-down menu to select a service.

However, when I attempt to do this, it doesn't work.  For example, this does not work:

image.png.e1af21517b3d43aba6c4c22c3866a81d.png

However, if I remove the service name and put in the full path to the executable the service is mapped to in services.msc, it works:

image.png.22814f7159bd120ceedb59733e87bb2f.png

Should ESET Server Security be able to work with a service only configuration or is that documentation not entirely accurate or not representative of how ESET Server Security works?  I was hoping this would work as several Microsoft products use different paths, depending on the version installed, for the same service.  For instance DPM includes the year in some versions, SQL Server includes the primary version ID, etc.  If this doesn't function as expected, then we would need to configure multiple rules for different versions.

Any input you can provide would be helpful (I contacted chat support and they seemed to indicate the help documentation was incorrect and a filepath is needed).

Jacob

 

Link to comment
Share on other sites

  • Administrators

If a service with that name exists in the system, you selected it in GUI and did not write it manually in an ESET PROTECT policy, it should work. Please raise a support ticket for further investigation why the rule was not evaluated unless you specified the path to the executable.

Link to comment
Share on other sites

Marcos,

I opened that support ticket as I am currently testing this directly in ESET Server Security; however, once we get this working as expected, we want to replicate this to ESET PROTECT and push it out via policy.  Is that not supported?

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...