| Name | Description |
| DNS Client | Name solving for vpn servers |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | Any |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 17 |
| Local port | Any |
| Remote port | 53 |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Zscaler Updater | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Program Files (x86)\Zscaler\ZSAUpdater\ZSAUpdater.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Zscaler Tunnel | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Program Files (x86)\Zscaler\ZSATunnel\ZSATunnel.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Zscaler TrayManager | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Program Files (x86)\Zscaler\ZSATrayManager\ZSATrayManager.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Zscaler Tray | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Program Files (x86)\Zscaler\ZSATray\ZSATray.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Zscaler Service | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Program Files (x86)\Zscaler\ZSAService\ZSAService.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Zscaler Helper | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Program Files (x86)\Zscaler\ZSAHelper\ZSAHelper.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| TP Sentinel Server | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | Any |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | 51.145.215.228 |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| TP Sentinel Speed Test | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | Any |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 6 |
| Local port | Any |
| Remote port | 8080, 80, 443 |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | 151.101.2.219, 151.101.66.219, 151.101.130.219, 151.101.194.219, 195.228.59.44, 89.40.72.167, 82.78.145.212, 89.37.212.119, 81.89.27.226, 91.209.189.112, 193.226.5.26, 95.77.34.198, 81.12.229.238, 51.145.215.228 |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Zscaler MTAuthApp | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Program Files (x86)\Zscaler\ZSATray\ZSAMTAuthApp.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Nessus Any | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | Any |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | 10.226.109.0/255.255.255.0, 10.226.120.0/255.255.255.0, 10.226.121.0/255.255.255.0, 10.226.220.0/255.255.255.0, 10.226.111.0/255.255.255.0, 10.226.112.0/255.255.255.0, 10.226.110.0/255.255.255.0, 10.226.224.0/255.255.255.0, 10.226.113.0/255.255.255.0, 10.226.226.0/255.255.255.0, 10.226.136.0/255.255.255.0, 10.17.129.3, 10.226.102.80, 10.226.202.204, 10.204.6.212, 10.204.8.164, 10.204.6.193, 10.204.8.183, 10.204.8.171, 10.204.8.175, 10.204.8.180, 10.204.8.170, 10.17.229.64/255.255.255.192, 10.226.125.0/255.255.255.0, 10.226.134.0/255.255.254.0, 10.226.203.0/255.255.255.0, 10.226.209.0/255.255.255.0, 10.226.211.0/255.255.255.0, 10.226.212.0/255.255.255.0, 10.226.213.0/255.255.255.0, 10.226.220.0/255.255.254.0, 10.226.225.0/255.255.255.0, 10.226.234.0/255.255.254.0, 10.226.237.0/255.255.255.0, 10.226.238.0/255.255.255.0 |
| Remote scope | 10.17.229.64/255.255.255.192, 10.204.8.170, 10.204.8.180, 10.204.8.175, 10.204.8.171, 10.204.8.183, 10.204.6.193, 10.204.8.164, 10.204.6.212, 10.226.202.204, 10.226.102.80, 10.17.129.3 |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow VPN Connectivity | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | Any |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | 91.240.4.0/255.255.255.0, 84.247.123.0/255.255.255.0 |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Internal TP RO | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | Any |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | 10.226.0.0/255.255.0.0 |
| Remote scope | 10.204.0.0/255.255.0.0, 10.33.1.134, 10.33.1.135, 10.17.129.3, 10.226.0.0/255.255.0.0, 10.17.229.64 |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Trafic trough VPN Chrome | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Program Files\Google\Chrome\Application\chrome.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 6 |
| Local port | Any |
| Remote port | 443 |
| ICMP settings | Any |
| Local scope | 10.226.109.0/255.255.255.0, 10.226.120.0/255.255.255.0, 10.226.121.0/255.255.255.0, 10.226.220.0/255.255.255.0, 10.226.111.0/255.255.255.0, 10.226.112.0/255.255.255.0, 10.226.110.0/255.255.255.0, 10.226.224.0/255.255.255.0, 10.226.113.0/255.255.255.0, 10.226.226.0/255.255.255.0, 10.226.136.0/255.255.255.0, 10.226.238.0/255.255.255.0, 10.226.237.0/255.255.255.0, 10.226.234.0/255.255.254.0, 10.226.225.0/255.255.255.0, 10.226.220.0/255.255.254.0, 10.226.213.0/255.255.255.0, 10.226.212.0/255.255.255.0, 10.226.211.0/255.255.255.0, 10.226.209.0/255.255.255.0, 10.226.203.0/255.255.255.0, 10.226.134.0/255.255.254.0, 10.226.125.0/255.255.255.0, 10.226.0.0/255.255.0.0 |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Troubleshooting Iexplorer | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Program Files\Internet Explorer\iexplore.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 6 |
| Local port | Any |
| Remote port | 443 |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | 91.240.4.242 |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Troubleshooting MSEdge | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 6 |
| Local port | Any |
| Remote port | 443 |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | 91.240.4.242 |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Trafic trough VPN Firefox | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Program Files\Mozilla Firefox\firefox.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 6 |
| Local port | Any |
| Remote port | 443 |
| ICMP settings | Any |
| Local scope | 10.226.109.0/255.255.255.0, 10.226.120.0/255.255.255.0, 10.226.121.0/255.255.255.0, 10.226.220.0/255.255.255.0, 10.226.111.0/255.255.255.0, 10.226.112.0/255.255.255.0, 10.226.110.0/255.255.255.0, 10.226.224.0/255.255.255.0, 10.226.113.0/255.255.255.0, 10.226.226.0/255.255.255.0, 10.226.136.0/255.255.255.0, 10.226.0.0/255.255.0.0 |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Trafic trough VPN Iexplorer | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Program Files\Internet Explorer\iexplore.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 6 |
| Local port | Any |
| Remote port | 443 |
| ICMP settings | Any |
| Local scope | 10.226.109.0/255.255.255.0, 10.226.120.0/255.255.255.0, 10.226.121.0/255.255.255.0, 10.226.220.0/255.255.255.0, 10.226.111.0/255.255.255.0, 10.226.112.0/255.255.255.0, 10.226.110.0/255.255.255.0, 10.226.224.0/255.255.255.0, 10.226.113.0/255.255.255.0, 10.226.226.0/255.255.255.0, 10.226.136.0/255.255.255.0 |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Troubleshooting Firefox | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Program Files\Mozilla Firefox\firefox.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 6 |
| Local port | Any |
| Remote port | 443 |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | 91.240.4.242 |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Troubleshooting Chrome x86 | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 6 |
| Local port | Any |
| Remote port | 443 |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | 91.240.4.242 |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Troubleshooting Chrome | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Program Files\Google\Chrome\Application\chrome.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 6 |
| Local port | Any |
| Remote port | 443 |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | 91.240.4.242 |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Trafic trough VPN MSEdge | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 6 |
| Local port | Any |
| Remote port | 443 |
| ICMP settings | Any |
| Local scope | 10.226.109.0/255.255.255.0, 10.226.120.0/255.255.255.0, 10.226.121.0/255.255.255.0, 10.226.220.0/255.255.255.0, 10.226.111.0/255.255.255.0, 10.226.112.0/255.255.255.0, 10.226.110.0/255.255.255.0, 10.226.224.0/255.255.255.0, 10.226.113.0/255.255.255.0, 10.226.226.0/255.255.255.0, 10.226.136.0/255.255.255.0, 10.226.0.0/255.255.0.0 |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Trafic trough VPN Chrome x86 | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 6 |
| Local port | Any |
| Remote port | 443 |
| ICMP settings | Any |
| Local scope | 10.226.109.0/255.255.255.0, 10.226.120.0/255.255.255.0, 10.226.121.0/255.255.255.0, 10.226.220.0/255.255.255.0, 10.226.111.0/255.255.255.0, 10.226.112.0/255.255.255.0, 10.226.110.0/255.255.255.0, 10.226.224.0/255.255.255.0, 10.226.113.0/255.255.255.0, 10.226.226.0/255.255.255.0, 10.226.136.0/255.255.255.0, 10.226.0.0/255.255.0.0 |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Trafic trough VPN Any Progranm | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | Any |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 6 |
| Local port | Any |
| Remote port | 443 |
| ICMP settings | Any |
| Local scope | 10.226.0.0/255.255.0.0 |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow ICMPv4 | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | Any |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 1 |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow IGMP | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | Any |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 2 |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| TP RO to TP RO and TP DE | 10.226.0.0/16, 10.204.0.0/16, 10.203.226.0/23 |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | Any |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | 10.226.0.0/255.255.0.0 |
| Remote scope | 10.226.0.0/255.255.0.0, 10.204.0.0/255.255.0.0, 10.203.226.0/255.255.254.0 |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| WSUS1803TCP | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | Any |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 6 |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | 10.226.102.62, 10.226.202.62 |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| WSUS1803UDP | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | Any |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 17 |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | 10.226.102.62, 10.226.202.62 |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Zscloud proxy | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | Any |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 6 |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | 185.46.212.0/255.255.254.0, 165.225.240.0/255.255.254.0, 147.161.172.0/255.255.254.0, 165.225.12.0/255.255.254.0, 196.23.154.96/255.255.255.224, 165.225.194.0/255.255.254.0, 147.161.160.0/255.255.254.0, 165.225.72.0/255.255.252.0, 147.161.164.0/255.255.254.0, 165.225.26.0/255.255.254.0, 197.98.201.0/255.255.255.0, 147.161.162.0/255.255.254.0, 154.113.23.0/255.255.255.0, 165.225.80.0/255.255.252.0, 147.161.166.0/255.255.254.0, 165.225.16.0/255.255.254.0, 165.225.92.0/255.255.254.0, 147.161.190.0/255.255.254.0, 165.225.196.0/255.255.254.0, 147.161.236.0/255.255.254.0, 165.225.198.0/255.255.254.0, 147.161.178.0/255.255.254.0, 147.161.180.0/255.255.254.0, 147.161.182.0/255.255.254.0, 165.225.202.0/255.255.254.0, 147.161.176.0/255.255.254.0, 147.161.168.0/255.255.254.0, 147.161.170.0/255.255.254.0, 213.52.102.0/255.255.255.0, 147.161.184.0/255.255.254.0, 165.225.20.0/255.255.254.0, 165.225.76.0/255.255.254.0, 165.225.204.0/255.255.254.0, 147.161.188.0/255.255.254.0, 165.225.192.0/255.255.254.0, 94.188.131.0/255.255.255.128, 165.225.200.0/255.255.254.0, 165.225.206.0/255.255.254.0, 165.225.94.0/255.255.254.0, 147.161.226.0/255.255.254.0, 147.161.230.0/255.255.254.0 |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| deffsap03.teleperformance.de | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | Any |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 6 |
| Local port | Any |
| Remote port | 44345 |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | 195.210.6.137, 88.84.147.104 |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Zscaler allow auth | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | Any |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 6 |
| Local port | Any |
| Remote port | 80 |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | 178.79.232.0/255.255.252.0, 152.199.23.0/255.255.255.0 |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Zscaler App Updater | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Program Files (x86)\Zscaler\Updater\zscalerappupdater.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow sharepoint_test | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | Any |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | 23.194.0.0/255.255.224.0 |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow UDP connections | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | Any |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 17 |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | 10.226.0.0/255.255.0.0 |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow HoYoverse | Allow SASE VPN |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | %ProgramFiles% (x86)\Aliyun\SASE\2.2.0\SASE.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow SMB to local networks | Microsoft Outlook Elevation of Privilege Vulnerability
CVE-2023-23397
Mitigations
The following mitigating factors may be helpful in your situation:
Add users to the Protected Users Security Group, which prevents the use of NTLM as an authentication mechanism. Performing this mitigation makes troubleshooting easier than other methods of disabling NTLM. Consider using it for high value accounts such as Domain Admins when possible. Please note: This may cause impact to applications that require NTLM, however the settings will revert once the user is removed from the Protected Users Group. Please see Protected Users Security Group for more information.
Block TCP 445/SMB outbound from your network by using a perimeter firewall, a local firewall, and via your VPN settings. This will prevent the sending of NTLM authentication messages to remote file shares. |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | Any |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 6 |
| Local port | Any |
| Remote port | 445 |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | 10.226.0.0/255.255.0.0, 10.20.0.0/255.255.0.0, 10.204.0.0/255.255.0.0, 10.144.0.0/255.255.0.0, 10.119.0.0/255.255.0.0, 10.33.0.0/255.255.0.0 |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Tanium | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | %ProgramFiles(x86)%\Tanium\Tanium Client\TaniumClient.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 6 |
| Local port | Any |
| Remote port | 17472, 17486 |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow TaniumCX | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | %ProgramFiles(x86)%\Tanium\Tanium Client\TaniumCX.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Hoyo Genshin | Allow game luncher for Genshin Impact |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Temp\Genshin Impact\launcher.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Hoyo StarRail | Allow game lucher for StarRail |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Temp\Star Rail\launcher.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Genshin2 | C:\Temp\Genshin Impact\Genshin Impact game\GenshinImpact.exe |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Temp\Genshin Impact\Genshin Impact game\GenshinImpact.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow StarRail | C:\Temp\Games\StarRail.exe |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Temp\Games\StarRail.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow StarRail2 | C:\Temp\Games\UnityCrashHandler64.exe |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\Temp\Games\UnityCrashHandler64.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Hoyo | 192.229.221.95 TCP 80 |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | Any |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 6 |
| Local port | Any |
| Remote port | 80 |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | 192.229.221.95 |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow SASE VPN | Allow SASE vpn version 3.5.5 |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | %ProgramFiles% (x86)\Aliyun\SASE\3.5.5\SASE.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Zscaler App Updater x64 | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | %programfiles%\Zscaler\Updater\zscalerappupdater.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Zscaler Helper x64 | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | %programfiles%\Zscaler\ZSAHelper\ZSAHelper.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Zscaler MTAuthApp x64 | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | %programfiles%\Zscaler\ZSATray\ZSAMTAuthApp.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Zscaler Service x64 | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | %programfiles%\Zscaler\ZSAService\ZSAService.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Zscaler Tray x64 | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | %programfiles%\Zscaler\ZSATray\ZSATray.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Zscaler TrayManager x64 | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | %programfiles%\Zscaler\ZSATrayManager\ZSATrayManager.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Zscaler Tunnel x64 | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | %programfiles%\Zscaler\ZSATunnel\ZSATunnel.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Zscaler Updater x64 | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | %programfiles%\Zscaler\ZSAUpdater\ZSAUpdater.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow TaniumCX | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | %ProgramFiles(x86)%\Tanium\Tanium Client\TaniumCX.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Tanium | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | %ProgramFiles(x86)%\Tanium\Tanium Client\TaniumClient.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow SASE VPN | Allow SASE vpn version 3.1.6 |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | %ProgramFiles% (x86)\Aliyun\SASE\3.1.6\SASE.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow SASE VPN | Allow SASE vpn version 3.8.5 |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | %ProgramFiles% (x86)\Aliyun\SASE\3.8.5\SASE.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow SASE VPN | Allow SASE vpn version 3.8.9 |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | %ProgramFiles% (x86)\Aliyun\SASE\3.8.9\SASE.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Hoyowave | CTASK000157981 |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\hoyo\HoYowave\HoYowave.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Hoyowave2 | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\hoyo\HoYowave\[1.3.7]\HoYowave.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Hoyowave Launcher | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\hoyo\HoYowave\[1.3.7]\Launcher.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Hoyowave Additional IP | 106.15.7.196 TCP 8999/8888 |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | Any |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | 6 |
| Local port | Any |
| Remote port | 8999, 8888 |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | 106.15.7.196, 47.254.124.240, 47.88.24.193, 10.217.112.199 |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Hoyowave | [1.4.8] |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | %localappdata%\hoyowave\[1.4.8]\hoyowave.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Hoyowave2 | 1.4.8 |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\hoyo\HoYowave\[1.4.8]\HoYowave.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow SASE VPN | Allow SASE vpn version 3.9.9 |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | %ProgramFiles% (x86)\Aliyun\SASE\3.9.9\SASE.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Hoyowave 2 | CTASK000157981 |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\hoyo\HoYowave\[1.12.6]\HoYowave.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Hoyowave2 | 1.13.6 |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\hoyo\HoYowave\[1.13.6]\HoYowave.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Hoyowave1.14.5 | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\hoyo\HoYowave\[1.14.5]\HoYowave.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Hoyowave1.16.0 | |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\hoyo\HoYowave\[1.16.0]\HoYowave.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|
| Allow Hoyowave2 | [1.17.2] |
| This rule might contain some elements that cannot be interpreted by the current version of GPMC reporting module | |
| Enabled | True |
| Program | C:\hoyo\HoYowave\[1.17.2]\HoYowave.exe |
| Action | Allow |
| Security | Require authentication |
| Authorized computers | |
| Protocol | Any |
| Local port | Any |
| Remote port | Any |
| ICMP settings | Any |
| Local scope | Any |
| Remote scope | Any |
| Profile | All |
| Network interface type | All |
| Service | All programs and services |
| Group | |
|