The Firewall payload allows admins to configure firewall rules for Android devices. Each firewall rule type allows you to add multiple rules.

The Firewall payload only applies to SAFE 2.0+ devices.


  1. Navigate to Resources > Profiles & Baselines > Profiles > Add > Add Profile > Android (Legacy).
  2. Select Device to deploy your profile.
  3. Configure the profile's General settings.
  4. Select the Firewall profile.
  5. Select the Add button under the desired rule to configure the settings:
    Setting Description
    Allow Rules Allows the device to send and receive from a specific network location.
    Deny Rules Blocks the device from sending and receiving traffic from a specific network location.
    Reroute Rules Redirects traffic from a specific network location to an alternate network. If an allowed website redirects to another URL, please add all redirected URLs to the Allow Rules section so it can be accessed.
    Redirect Exception Avoids traffic from being redirected.
  6. Select Save & Publish.
    The Firewall configuration is an IP Address based tool, and adding hostnames will not work as well as IP addresses. Services such as Google and Amazon do not always maintain static IP addresses so using hostnames is recommended, but may result in inconsistencies.