Next Topic

Previous Topic

Book Contents

Network Access

The Network Access page lets you approve or deny TCP/IP-protocol-based network access on a per application basis. Users can also be notified when an unlisted application accesses the network, permitting or denying that application network access. Typically this function is used to control access to internal and external internet sites, but can include internal LAN traffic that also uses the TCP/IP protocol.

Driver

This function requires the driver be enabled to block network access and monitor network bandwidth statistics. The driver is disabled by default. This driver inserts itself into the TCP/IP stack to measure TCP/IP-protocol-based network traffic by application. For Windows machines earlier than Vista, an enabled driver only takes effect after a reboot of the machine.

Note: To determine which applications should be approved or denied network access, use the Network Statistics report to view network bandwidth utilization versus time. Drill down and identify peak bandwidth consumers by clicking the graph's data points. See which application and which machine use bandwidth at any point in time.

Warning: Applications that do not use the Windows TCP/IP stack in the standard way may conflict with the driver used to collect information and block access, especially older legacy applications.

Multiple Agents

If multiple agents are installed on a machine, only one agent at a time controls the drivers required to use File Access, Network Access, Application Blocker. These functions can only be performed by the agent controlling these drivers.

To approve or deny network access to one or more applications

  1. Check the checkbox next to one or more machine IDs in the Machine.Group ID column.
  2. Click the link of any machine ID in the Machine.Group ID column. It does not have to be the machine ID you checked. This displays the Application List popup window, listing all applications installed on that machine ID. The list is based on the latest audit that was performed for that machine ID.
  3. Since the list in the Application List window may be large, you can control the applications displayed by clicking Filter to filter the list.
  4. Check the checkboxes next to the application name you wish to approve or deny network access to.
  5. You can also enter application names in the Add applications not found by audit here edit field, to identify applications not listed.
  6. Click the Select button to confirm your selections and close the Application List window. The selected applications now display at the top of the page.
  7. Click Approve Apps or Deny Apps. The applications selected in the Application List window are added from the Approved Apps/Denied Apps column.

To remove approve and deny settings for one or more machine IDs

  1. Check the checkbox next to one or more machine IDs in the Machine.Group ID column.
  2. Click the Remove Apps button.

Network Access Options

Select All/Unselect All

Click the Select All link to check all rows on the page. Click the Unselect All link to uncheck all rows on the page.

Check-in status

These icons indicate the agent check-in status of each managed machine. Hovering the cursor over a check-in icon displays the agent Quick View window.

Word 50% / HTML 50% Online but waiting for first audit to complete

Word 50% / HTML 50% Agent online

Word 50% / HTML 50% Agent online and user currently logged on.

Word 50% / HTML 50% Agent online and user currently logged on, but user not active for 10 minutes

Word 50% / HTML 50% Agent is currently offline

Word 50% / HTML 50% Agent has never checked in

Word 50% / HTML 50% Agent is online but remote control has been disabled

Word 50% / HTML 50% The agent has been suspended

Word 80% / HTML 80% An agent icon adorned with a red clock badge is a temporary agent.

Machine.Group ID

The list of Machine.Group IDs displayed is based on the Machine ID / Group ID filter and the machine groups the user is authorized to see using System > User Security > Scopes.

Notify User

A green checkmark in the Notify User column indicates that the managed machine user is notified when an application attempts to access the network that has been denied network access.

To notify the user when a application has been denied:

  1. Select machine IDs.
  2. Click the Enable button for Notify user when app is blocked.

To remove this notification:

  1. Select machine IDs that display a green checkmark in the Notify column.
  2. Click the Disable button for Notify user when app is blocked.

Enable Driver

Identifies on a per machine ID basis, which machines have the network protection driver enabled or not. For Windows machines earlier than Vista, an enabled driver only takes effect after a reboot of the machine.

Unlisted Action

Displays the Unlisted Action to take when an unlisted application attempts to access the network. See Apply Unlisted Action above.

Approved Apps / Denies Apps / Remove Apps / Remove All

These settings can only be applied once the driver is enabled.