Consider that when an application equipped with an MD5 Hash is used on multiple clients, file versions need to match exactly. Otherwise, the application object will not be applicable.

Click Clear to delete the hash.

In addition to the application, first level DLLs are taken into consideration. This provides additional security. However, DLLs used by first level DLLs are not monitored.

The following application objects, that are required in Microsoft Windows domains, are available within the Barracuda NG Personal Firewall by default:

Table 3–6Applications required in Microsoft Windows domains

Application

 

Connection

Description

 

 

 

 

System

 

O / I

Services needed by the OS kernel

 

 

 

 

TCP/IP

Ping

O / I

 

Command

 

 

 

 

 

 

 

lsass.exe

 

O

Local Security Authority Service; process responsible for management of local security authority domain

 

 

 

authentication and Active Directory management.

 

 

 

 

services.exe

 

O

Upon startup, services.exe enumerates through all registry sub-keys located in

 

 

 

HKEY_LOCAL_MACHINE\Services registry key.

 

 

 

 

spoolsv.exe

 

O

The Windows Printer Spooler stores printer jobs and forwards them to the printer when it is ready.

 

 

 

 

userinit.exe

 

O

By default, WinLogon executes this application that triggers logon scripts, re-establishes network

 

 

 

connections,…

 

 

 

 

winlogon.exe

 

O

This application manages security-related user interactions in Windows NT. It handles logon and logoff

 

 

 

requests, changing the password,…

 

 

 

 

svchost.exe

 

O

This is a generic host process name for services that are run from dynamic-link libraries (DLLs). There

 

 

 

can be multiple instances of svchost.exe running at the same time.

 

 

 

 

61 Barracuda NG Network Access Client - Administrator’s Guide

Page 63
Image 63
Barracuda Networks VERSION SP4 manual Application Connection Description, HKEYLOCALMACHINE\Services registry key