Product guide

Desktop firewall monitors the PORT, EPRT, PASV, and EPSV commands on the control channel, and
determines which dynamic rules must be created for subsequent FTP data connections.
The combination of the control connection and one or more data connections is called a session. When
the data transfer is complete, the dynamic rules created for data transfer are removed.
When the control connection is terminated, desktop firewall makes sure that all corresponding data
connections are also removed.
How desktop firewall rules work
Each rule contains a set of conditions that the network traffic must meet. The associated parameters
of that rule allow or block the network traffic.
This diagram shows how network packet filtering works.
This diagram explains how the process rule table flow works for each network packet.
Configuring protection preferences on a standalone Mac
Desktop firewall
4
McAfee Endpoint Protection for Mac 2.1.0 Product Guide
47