Product guide
4
Select the options, then click Save.
From... Set these options...
Firewall status
Enabled — To enable desktop firewall protection on managed Mac.
• Regular protection — To allow network traffic, only when the network packet
adheres to the rule's conditions.
• Adaptive mode — To create an allow rule, when the network packet does not
match the existing rule.
Firewall client rules
Retain existing client rules when this policy is enforced — To retain the rules that are created
by the client Mac when you enforce this policy.
Stateful firewall
settings
FTP protocol inspection — Add a value for TCP connection timeout (in seconds) and UDP and
ICMP echo virtual connection timeout (in seconds).
5
Send an agent wake-up call.
If the desktop firewall protection is disabled from ePolicy Orchestrator, the security status of the
managed Mac still appears that Your Mac is Secure.
Create firewall rules
Define rules and parameters to allow or block a particular network's traffic.
Task
For option definitions, click ? in the interface.
1
Log on to the ePolicy Orchestrator server as an administrator.
2
From the Policy Catalog, select Host Intrusion Prevention 8.0: Firewall as the product, then select Firewall Rules
(Windows, Mac) as the category.
3
Click New Policy, type a name for the policy, then click OK to open the policy page.
4
Click New Rule, type a name for the policy, then click OK to open the Firewall Rule Builder page.
5
On the Description tab, define options, then click Next.
From... Configure these options...
Name
Type a name for the rule.
Action
• Allow — To allow traffic.
• Block — To block traffic.
If you select Block, the Treat match as intrusion option is enabled. But this option is for
Windows Only.
Select Log matching traffic, if needed.
Direction
• In — To apply the rules for incoming traffic.
• Out — To apply the rules for outgoing traffic.
• Either — To apply the rules for incoming and outgoing traffic.
Status
• Enabled — To enable the rule on the managed Mac.
• Disabled — To disable the rule on the managed Mac.
6
Define options on the Network Options page, then click Next.
Managing the software with ePolicy Orchestrator
Desktop firewall policy
5
McAfee Endpoint Protection for Mac 2.1.0 Product Guide
65