Issue
- Allow self-enrollment communications through the Windows Firewall of a system that is hosting ESET Endpoint Encryption Server
- Allow self-enrollment communications by application exclusion
- Allow self-enrollment communications by port exclusion
Details
The steps described below are for the software firewall provided with Windows Server 2012 R2. Steps may vary on other editions of Windows. You may need to make similar changes to hardware firewalls if present to allow communications.
There are two methods to allow communications; only one of the methods needs to be used:
Solution
Application exclusion
-
Press the Windows
key on your keyboard and type
control panel
. Click Control Panel.
![](/storage/IMAGES/en/KB8056/KB8056Fig1-1.png)
-
Click System and Security.
![](https://support.deslock.com/resources/KB426/KB426_016.png)
- Click Allow an app through Windows Firewall.
![](https://support.deslock.com/resources/KB426/KB426_015.png)
- Click Allow another app.
![](https://support.deslock.com/resources/KB426/KB426_014.png)
- Click Browse.
![](https://support.deslock.com/resources/KB426/KB426_013.png)
- Browse to
C:\Program Files (x86)\ESET Endpoint Encryption Server
and select dlpecsrv. Click Open.
![](/storage/IMAGES/en/KB8056/KB8056Fig1-6.png)
- Click Network types.
![](https://support.deslock.com/resources/KB426/KB426_011.png)
- Select the check box next to Domain: Networks at a workplace that are attached to a domain and click OK.
![](/storage/IMAGES/en/KB8056/KB8056Fig1-8.png)
- Confirm that ESET Endpoint Encryption Server Console Service is listed and click OK.
![](/storage/IMAGES/en/KB8056/KB8056Fig1-9a.png)
Port exclusion
-
Press the Windows
key on your keyboard and type
control panel
. Click Control Panel. -
Click System and Security.
-
Click Windows Defender Firewall.
![](https://support.deslock.com/resources/KB426/KB426_008.png)
- Click Advanced settings.
![](https://support.deslock.com/resources/KB426/KB426_007.png)
- Select Inbound Rules and click New Rule.
![](/storage/IMAGES/en/KB8056/KB8056Fig2-3.png)
- Select Port and click Next.
![](/storage/IMAGES/en/KB8056/KB8056Fig2-4.png)
- Select TCP, ensure that Specific local ports option is selected, and type
8266
in the Specific local ports field. Click Next.
![](/storage/IMAGES/en/KB8056/KB8056Fig2-5.png)
- Select Allow the connection and click Next.
![](/storage/IMAGES/en/KB8056/KB8056Fig2-6.png)
- Deselect the check boxes next to Private and Public and ensure that only the check box next to Domain is selected. Click Next.
![](/storage/IMAGES/en/KB8056/KB8056Fig2-7.png)
- Type a name for the rule in the Name field and click Finish.
![](/storage/IMAGES/en/KB8056/KB8056Fig2-8.png)
- Repeat the process from the Port exclusion section but select UDP as the type instead of TCP in Step 7.