Sophos

Online support

Product maintenance

Contact support

Support services

Sophos Client Firewall: merging rules

You can add specific applications to the policy for Sophos Client Firewall by merging Sophos Client Firewall policy configuration files. These can either be ones that you have built, or files for particular applications that you have downloaded from our website.

This article contains instructions on how to merge preset rules for common applications into your Sophos Client Firewall policy. Instructions are included for both standalone and networked computers.

What to do

To merge a policy file on a single workstation

  1. Download (or otherwise obtain) the configuration file for the application you need.
  2. Open the Sophos Client Firewall configuration page.
  3. In the General tab, click 'Import'.
  4. Browse to the configuration file you downloaded.
  5. Click 'Open'.
  6. You will be asked to specify how you want to import the configuration file.
    • Deselect the 'Load the general configuration' checkbox.
    • Ensure that the 'Load the global and application rules' checkbox is selected.
    • Select 'Merge'.
  7. Click 'OK'.

To merge a firewall configuration file into your network firewall policy

  1. Download (or otherwise obtain) the configuration file for the application you need.
  2. In Sophos Enterprise Console, right-click the firewall policy you want to change.
  3. Select 'View/Edit policy'.
  4. In the General tab, click 'Import'.
  5. Browse to the configuration file you downloaded.
  6. Click 'Open'.
  7. You will then be asked to specify how you want to Import the configuration file.
    • Deselect the 'Load the general configuration' checkbox.
    • Ensure that the 'Load the global and application rules' checkbox is selected.
    • Select 'Merge'.
  8. Click 'OK'.
  9. All of the computers using this policy will now be marked as 'Differs from policy'.
  10. Select these computers, right-click them, and select 'Comply with group firewall policy'.

If you need more information or guidance, then please contact technical support.