Previous Topic: Known IssuesNext Topic: CFSA Can Prevent BitLocker From Encrypting USB Devices


Firewall Configuration on Endpoints

The CA Data Protection installation wizard automatically registers the CA Data Protection infrastructure as a firewall exception. This enables data, including policy updates, to replicate unhindered through the firewall between CA Data Protection endpoints and servers. However, you must disable the 'exception blocking' feature in the Windows firewall to allow the CA Data Protection exceptions.

Endpoints on Windows 2003

Clear the ‘Don’t allow exceptions’ check box. Find this setting on the General tab of the Windows Firewall applet.

Endpoints on Windows Vista, Windows 7, and Windows 8

Clear the 'Block all incoming connections' option. Find this option in the 'Domain network settings' section of the Windows Firewall applet.

Endpoints on Windows Server 2008 and Windows Server 2012

Clear the 'Block all incoming connections' option. Find this option in the 'Domain network settings' section of the Windows Firewall applet.

Note: CA Data Protection endpoint agents support 'centralized applications' running on Windows Server. For these deployments, users access applications such as Outlook on a central server using, for example, Citrix or Remote Desktop Connection.

Important! If you do not clear the checkbox or options described above, these firewall settings remain enabled. Consequently, the Windows Firewall allows no firewall exceptions. It therefore blocks the CA Data Protection infrastructure, which prevents the CA Data Protection endpoint computers from contacting its parent server. In particular, endpoint agents cannot receive any user or machine policies. The endpoint agents are therefore paralyzed and cannot capture or control user activity.