- Server Edition
- Windows 7 Firewall Control Server Edition allows you to set application network
access permission individually per-user. As the result, you can set zones for Administrator, Guest and any other user for a particular application separately. The feature is extremely useful with Terminal Server (Windows Server 2008 or Windows 7 Server), however, the Server Edition can be launched on any Vista and Windows 7 running computer. - You can determine Internet Explorer (for instance) is able to connect to any site for administrators, to corporate local network web server only for regular users and unable to browse any web server for guests.
- How to configure the per-user access
- The "User" column shows the username for application and access zone set in the Programs tab of Windows 7 Firewall Control Server Edition. The "User" parameter can be changed with Edit Application dialog by the user selection option available in Server Edition only. You can set a separate zone to every separate user registered on the computer, server or the domain.
- The following per-user management logic must be supposed. If a specific user is set to an application with a zone the application will follow the chosen access zone when the application is launched in name of the user only. If the application with the zone is set to "Any User", the application will follow the zone when the application is launched in name of all the other users.
- For example, you have Internet Explorer set to Web+FTPZone for "Any User", Internet Explorer set to DisableAll for Guest and Internet Explorer set to LocalOnly for JohnSmith. As the result, Internet Explorer will follow the rules for the users above as specified and Web+FTPZone for the other users including Administrators, regular users and so on.
- Please bear in mind Windows 7 Firewall Control is able to detect non-listed applications only, so if you have an application set to a specific user and do not have the application set to "Any User", the application launched in name of any other user will not be detected for the second time and will be entirely blocked as any other initial access attempt is blocked. The hint may be used to create special security schemes however.
|