Hi.
I'm probably being a numpty here - only just getting used to the network threat protection in SEP - it's currently in test.....
To test the blocking of appliations I created a copy of the default firewall policy and applied it to my test group - I then created a block rule (above the blue line) which should block Lotus notes on the network and Internet Explorer....I used these because they're used all the time....
So I specified the applications from the learned applications list....I'm pretty sure i've covered all the ltous notes components - and I chose IE from the learned list too....all show file fingerprint and location....but, it hasn't worked...not a sausage...no network blocking, and my test group can use notes and IE as normal....
what gives? here's a screenshot of the test firewall policy....the rule is rule no.7 - this is aplied to my test group for both locations
I had used this policy before to 'Ask' for traffic going out, that seemed to work, I did that by changing rules no.10 and 13 to 'Ask' instead of 'Allow'