Skip to main content

App Controls Rules on Zenconsole

Published on:
.
4 min read

Zenarmor Application Control identifies and classifies the applications associated with network connections. It uses the Zenarmor Application Database (App DB), which contains dynamically updated signatures that help the packet engine identify application traffic.

Application Control rules allow you to block or allow entire application categories or selected applications within a category. These rules apply to traffic that matches the policy's configuration and matching criteria.

tip

Web Controls are evaluated before Application Controls. If a connection is blocked by a Web Control rule, it does not proceed to Application Control processing. As a result, application information for that session may not appear in related reports.

To access the Application Control settings for a policy, follow the steps below:

  1. Sign in to Zenconsole.
  2. Select the organization you want to manage.
  3. Navigate to Policies > Internet Security Policies.
  4. Select the policy you want to configure.
  5. Navigate to the App Controls tab.

The App Controls page displays the application categories available in the Zenarmor Application Database.

Figure 1. App Controls

Understanding the App Controls Page

The All Categories table provides the following information for each application category:

  • Category Name: Identifies the application category.
  • Number of blocked sub-categories: Shows the number of blocked items compared with the total number of items available in the category.
  • Status: Indicates whether the category is currently allowed, blocked, or customized.

The following status values may appear:

  • Allowed: No subcategories within the category are blocked.

  • Custom: Some, but not all, subcategories within the category are blocked.

  • Blocked: The entire category and its subcategories are blocked.

    Figure 2. Understanding the App Controls

The Custom status is assigned automatically when the allowed and blocked settings within a category are modified individually. It is not a separate status that you select manually.

For example, a value of 258 / 263 indicates that 258 of the 263 subcategories are blocked. Because some subcategories remain allowed, the category status is displayed as Custom.

note

The number of applications or subcategories in a category may change as the Zenarmor Application Database is updated. Counts shown in documentation images are examples and may differ from those displayed in your organization.

Searching for App Categories and Applications to Filter

You can use the Search field at the top of the App Controls page to locate a specific category or application.

To search for an application category or application:

  1. Navigate to the policy's App Controls tab.
  2. Enter all or part of the name in the Search field.
  3. Review the matching results.
  4. Select the applicable category or application to review its current status.

The results are filtered dynamically as you type. Each listed item displays its current status and provides a toggle for changing its behavior.

Figure 3. Searching for an Application Category or Application

Blocking or Allowing an Application

You can configure applications or subcategories individually without blocking the entire parent category.

To block or allow an individual application:

  1. Open the applicable category from the All Categories table.
  2. Locate the application you want to configure.
  3. Enable the toggle next to the application to block it.
  4. Disable the toggle to allow it.

When you change individual items, Zenconsole automatically updates the number of blocked subcategories displayed for the parent category.

If the category contains both allowed and blocked items, its status changes to Custom.

Figure 4. Blocking an Application

Blocking or Allowing an Entire Category

You can block or allow every application contained in a category from the All Categories table.

To configure an entire category:

  1. Navigate to the policy's App Controls tab.
  2. Locate the category you want to configure.
  3. Enable the toggle next to the category to block it and its subcategories.
  4. Disable the toggle to allow the category and its subcategories.

When the entire category is blocked, the blocked subcategory count reflects the total number of items in that category and its status is displayed as Blocked.

Figure 5. Blocking an entire application category

warning

Changing the status of an entire category affects every application and subcategory contained in it. Review any existing custom selections before applying the change.

Applying Application Control Changes

After configuring the Application Control rules, ensure that the policy is enabled.

Policy changes are automatically synchronized with associated gateways and endpoints within a maximum of 15 minutes. To distribute the changes immediately, return to the Internet Security Policies page and click Sync Now.

For detailed synchronization instructions, see Policy Synchronization.

Verifying Application Control Rules

After enabling the policy and synchronizing the changes, you can verify an Application Control rule from a gateway or endpoint that matches the policy.

You can test a rule configured for either an individual application or an entire application category:

  1. Confirm that the application or category you want to test is blocked:
    • If an individual application is blocked, open its parent category and verify that the toggle next to the application is enabled. The parent category is displayed with a Custom status.
    • If the entire category is blocked, verify that the category is displayed with a Blocked status and that the number of blocked subcategories matches the total number of subcategories.
  2. From a device to which the policy applies, attempt to access the blocked application.
  3. Verify that access is denied.

In the following example, the entire A.I. Tools category is blocked. The value 136 / 136 indicates that all applications within the category are blocked.

Figure 6. Blocked A.I. Tools application category

When a user covered by the policy attempts to access an application in this category, such as Google Gemini, Zenarmor displays a block page indicating that access was denied according to the organization's policy. The page also displays the reason for the block, such as A.I. Tools category access.

A similar result occurs when only the individual application being accessed is blocked, even if the other applications in its parent category remain allowed.

Figure 7. Application access blocked by an Application Control rule

note

The result displayed to the user may vary depending on the application, protocol, browser, and deployment type. Browser-based traffic may display a Zenarmor block page, while traffic from some applications may be terminated without displaying a block page.

You can also review Live Sessions or Reports to examine the blocked connection and confirm which policy, application, or application category caused the action.