Allow connection rules override program deny rules

Hi all,

we're currently migrating from another endpoint product to EPDR and ran into a design issue with the firewall rule evaluation that I'd like to raise as a feature request.

Right now connection rules always take priority over program rules. In practice this means: if you have an allow connection rule for outbound traffic (say TCP 443 to some destination), it silently overrides any deny program rules underneath it. We block outbound connections for powershell.exe, certutil.exe, curl.exe etc. as a hardening measure, but as soon as a broader allow connection rule matches, those binaries can talk to the internet again. The only workaround is to never create outbound allow connection rules that aren't pinned to specific internal IPs, which works but is easy to get wrong and hard to audit.

The same problem exists the other way around. A necessary allow program rule like svchost.exe on 80/443 would punch through connection-level deny rules if the priorities were simply swapped, so changing the order wouldn't fix anything either.

What would actually solve this: make deny rules win over allow rules regardless of whether they are connection or program rules. That's how the Windows firewall handles it (block beats allow) and it would let both rule types coexist as independent safety nets instead of one layer being able to accidentally disable the other.

Comments

  • Hi @19steffen91

    If you can be so kind as to open a support ticket with the support department, we will provide steps for submitting an enhancement request for our products.


    David Carro | Technical support
    WatchGuard Technologies, Inc. | www.watchguard.com