Changing the firewall rule order Symantec Endpoint Security (SES).
The firewall processes the firewall rules in the order they are listed in the Firewall policy. If the first rule does not specify how to handle a packet, the firewall inspects the second rule. This process continues until the firewall finds a match. After the firewall finds a match, the firewall takes the action that the rule specifies. Subsequent lower priority rules are not inspected. For example, if a rule that blocks all traffic is listed first, followed by a rule that allows all traffic, the client blocks all traffic.
Determine how the firewall processes firewall rules by changing their order. For better protection, place the most restrictive rules first and the least restrictive rules last.
The below table (Processing Order) shows the order in which the firewall processes the rules, firewall settings, and intrusion prevention settings.
Table: Processing order
Priority |
Setting |
First |
Intrusion Prevention settings, traffic settings, and stealth settings |
Second |
Built-in rules |
Third |
Firewall rules |
Fourth |
Port scan checks |
Fifth |
IPS signatures that are downloaded through Live Update. |