Please add Move button to App Patrol Profile page

MpDay Posts: 7  Freshman Member
First Comment Second Anniversary
edited April 2021 in Security

Hi, can you please add a Move button in order to give Priority to the App Patrol rules? Right now, rule 4 has ALL application with reject, and the rules above have a forward action, so this works great. However, if I'm going to change/add profiles, the priority gets messed up. I need to be able to move rules and give them priority e.g. the reject rule always needs to be below the forward rules.

All Replies

  • sk8erbender
    sk8erbender Posts: 74  Ally Member
    First Comment Friend Collector Second Anniversary
    Hi , can I ask you why do u make such rule?  I personally made from LAN1 to WAN only 443,80 port tcp . with Content filtering, idp,adp,antivirus.
    Also rule for another server with dns crypt , all other rules deny
     Then Rule from LAN1 to WAN any any deny

    I mean can you explain this Network_protocols , streaming media and web ?
  • MpDay
    MpDay Posts: 7  Freshman Member
    First Comment Second Anniversary
    edited December 2018
    Hi, this is a screenshot from one of our test units, so the rules are not for production use. However, we create this type of policy in order to achieve maximum application logging/insight in used applications, and apply zero trust policy. So we only allow the apps in the forward rules, and then we reject everything. (same as how the security policy works, the final rule is any-any: deny).
  • Zyxel_Emily
    Zyxel_Emily Posts: 1,405  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments
    Hi @MpDay,

    The goal you'd like to achieve is to allow only one/certain applications and block all other applications. Is it right?

    In the App Patrol profile, there is no priority for each application.
    Each application will be forwarded/dropped/rejected based on its own action.
    If you'd like to forward a certain application, this application cannot be on the reject list of application. 
    The design of application profile is not the same as security policy rule.

    See how you've made an impact in Zyxel Community this year!