EDR Firewall gives you complete control over every inbound and outbound connection on your network, pairing enterprise-grade protection with the flexibility to define exactly what is allowed and what is blocked. Choose from four security levels – from total lockdown to flexible monitoring – and fine-tune access with granular exception rules. Built-in alerts and reporting keep you informed the moment traffic is allowed or denied.
1. FOUR SECURITY LEVELS, TAILORED TO YOUR NEEDS
Each level changes how the firewall treats inbound and outbound traffic, so you can match protection to your environment:
- HIGHEST – Maximum lockdown. Blocks all inbound and outbound connections with no exceptions. Nothing gets through.
- HIGH – Strong protection. Blocks all inbound and outbound connections except the exceptions you explicitly add.
- MEDIUM – Balanced control. Blocks all inbound traffic while allowing outbound connections, minus any user-defined exceptions.
- LOW – Flexible monitoring. Allows all inbound and outbound connections except those you choose to block.
2. EXCEPTION MANAGEMENT – RULES ON YOUR TERMS
When a level alone is not precise enough, exceptions let you carve out exactly the access you need. Every exception can be named, then configured across these dimensions:
- Protocol – TCP, UDP, ICMP, or Any.
- Direction – Inbound, outbound, or both.
- Action – Allow or block the matching traffic.
- Remote IP – Any address, a single specific address, or an address range (start to end).
- Remote ports – Any port, specific ports (comma-separated), or a port range (start to end).
- Local ports – Any port or specific ports (comma-separated).
- Application path – Apply the rule to a specific application or to all applications.
Manage your rule set with ease: add, edit, and delete exceptions, search across every rule, or apply a set of default rules to get started fast. Enable Firewall Alerts for real-time notifications and Firewall Reports for a full audit trail of allowed and blocked connections.
3. CENTRALIZED, CROSS-PLATFORM MANAGEMENT
EDR Firewall is our own firewall engine, deployed through the EDR agent and managed entirely from the central console – so you control protection across Windows Server and Linux endpoints from a single pane, with no need to log in to each machine.
- WINDOWS/LINUX SERVER – The same firewall engine runs on Windows/Linux endpoints via the EDR agent, applying identical levels and rules across your environment.
- REMOTE RULE LIFECYCLE – Add, modify, and delete firewall rules across single endpoints or entire server groups in one action.
- STATE ENFORCEMENT – Turn the EDR firewall on or off, lock it to a required state, and prevent local tampering by users on the endpoint.
- VISIBILITY – Read and report the current firewall status and rule set for every managed endpoint.
4. APPLICATION-AWARE & CATEGORY-BASED CONTROL
The firewall governs network activity at the application level – by individual program or by application category – and combines that with full packet, protocol, address, port, and direction control.
- BY CATEGORY – Classify applications into categories (web browsers, P2P / torrent clients, remote-access tools, messaging, cloud storage, and more) and allow or block an entire category in a single rule.
- BY APPLICATION – Target a specific executable by path when you need finer control than a category allows.
- PACKET & PROTOCOL – Match on TCP, UDP, ICMP, or Any.
- IP ADDRESS – Any address, a single host, or a start-to-end range.
- PORTS – Remote and local ports: any, specific (comma-separated), or a range.
- DIRECTION & ACTION – Inbound, outbound, or both; allow or block the matching traffic.
This lets you stop a whole class of network activity – for example, blocking all P2P traffic – without naming every executable.