Citrix Endpoint Management

Firewall device policy

This policy lets you configure firewall settings for Samsung, macOS, and Windows devices.

To add or configure this policy, go to Configure > Device Policies. For more information, see Device policies.

macOS settings

Requires macOS 10.12 and later.

Device Policies configuration screen

  • Enable Firewall. To enable the firewall, set this option to On.
  • Block all incoming connections. When this option is set to On, it blocks all incoming connections except the connections required for basic services.
  • Enable stealth mode. In stealth mode, the device doesn’t respond to or acknowledge attempts to access it from the network by test applications using ICMP, such as Ping. To enable stealth mode, set this option to On.
  • App specific incoming connection settings. To allow specific apps to receive connections, add the apps and set Allowed to True.

Windows Desktop and Tablet settings

Requires Windows Desktop and Tablet devices running Windows 10 (version 1709 or later) or Windows 11.

Device Policies configuration screen

  • Enable Feature: Controls incoming and outgoing traffic on computers to which this policy is deployed. Default is On.
  • Public Profile: Controls Windows Firewall while computers are connected to untrusted networks at public places, such as at an airport or coffee shop. Default is On.
  • Private Profile: Controls Windows Firewall while computers are connected to trusted networks, such as their home network. Default is On.
  • Domain Profile: Controls Windows Firewall while the computers are connected to the domain networks, such as at their workplace. Default is On.
  • Block all incoming connections, including those in the list of allowed programs: Default is Off.
  • Disable notifications to user when Firewall blocks a new program: Default is Off.
Firewall device policy