Sophos

Online support

Product maintenance

Contact support

Support services

Sophos Client Firewall: security implications of editing Global Rules

Global rules apply to all network connections. They take lower priority than the rules you set on the LAN tabbed page. They also take lower priority than rules set on the Applications tabbed page, unless you select 'High priority' when you set up the global rule.

A knowledgebase article describes the default settings for the Global Rules and other tabbed pages.

Global Rules tabbed page

The uppermost rule in the list has the highest priority. You can move rules up and down the list with the 'Move Up' and 'Move Down' buttons.

Default rule set

Default rules for Enterprise Console

Adding rules

When adding new rules, remember that the more information you include in your rule, the more secure it will be.

If you are adding a new application, rather than trusting everything that it might do, you can limit its use. For example you can:

This will limit how the user can use the application, and will be more secure.

Alone, the components of a rule mean little in security terms, but when used in conjunction with each other, they can allow an application to be used freely, but securely.

Other Sophos Client Firewall pages

Further knowledgebase articles describe the security implications of changing other options:

If you need more information or guidance, then please contact technical support.