FortiClient Manager : Configuring FortiClient agent settings : Creating firewall policies on a FortiClient agent
 
Creating firewall policies on a FortiClient agent
Firewall policies are instructions that the FortiClient program uses to decide what to do with a connection request. When managed by a FortiManager unit, the FortiClient firewall operates in Custom Profile mode.
Create global firewall policies to control traffic generally. These policies create FortiClient advanced firewall rules.
Create application firewall policies to control specific applications’ access to the network. These policies create FortiClient advanced application firewall rules.
Create New
Create a firewall policy.
Override
The FortiClient agent’s configuration includes those inherited from the group to which the computer belongs.
Selecting override allows you to modify the inherited firewall policy on this FortiClient agent. Deselecting override means that you want to use the firewall policy inherited from the group to which the computer belongs.
Even with inherited firewall policies, you can still create new firewall policies for a FortiClient agent.
Name
The policy name.
Application
For an application policy, select the application. If the application is not listed, go to Application > Application in the FortiClient menu. See “Defining firewall applications on a FortiClient agent”.
Source
The source address to which the policy applies. See “Configuring firewall addresses on a FortiClient agent”.
Destination
The destination address to which the policy applies. See “Configuring firewall addresses on a FortiClient agent”.
Schedule
The schedule that controls when the policy should be active. See “Configuring firewall schedules on a FortiClient agent”.
Protocol
The service to which the policy applies. See “Defining firewall protocols on a FortiClient agent”.
Action
The response to make when the policy matches a connection attempt: Allow or Block.
Enable
Enable or disable the policy. Enabling the policy makes it available for the firewall to match it to incoming or outgoing connections.
Action
Select the Delete icon to remove a policy, and Edit icon to modify a policy.
To create a firewall policy:
1. In the FortiClient Manager, select Client/Group > Client > Managed Client in the navigation pane.
2. In the All Managed Clients list, select the FortiClient agent you want to configure from the Host Name column.
3. From the FortiClient menu, select one of the following:
for a general firewall policy, Firewall > Policy > Global Policy
for an application-specific policy, Firewall > Policy > Application Policy
4. Select Create New.
5. Enter the field value as described above and then select OK.