How to Add Exceptions to Norton 360 Firewall

Here’s how to add exceptions to Norton 360 Firewall: open Norton device security, go to Settings > Firewall > Program Control, select Add, browse to the application’s executable file, and click Open. Norton checks the file’s reputation and displays a recommended access setting. For an application listed in Smart Firewall, you can create or edit a Program Control rule, set its Action to Allow, and select Save.

Program Control exceptions manage an application’s Internet and network access, not antivirus scan exclusions. Keep Automatic Program Control in Smart Mode unless a specific application needs an override, as Norton warns that changing firewall rules can reduce security. Port-based exceptions use Traffic Rules, which are processed before Program rules.

How to Add Exceptions to Norton 360 Firewall

These workflows have different confirmation steps: adding an executable through Program Control produces a reputation-based Security Alert, while Add app rule lets you define and save a rule directly. Before adding anything, check whether the application already appears in Program Control. Norton automatically adds programs when they first attempt to connect to the Internet or a network, so an existing entry may already be ready to review.

Add an Executable Through Program Control

  1. Open Norton device security. If the My Norton window appears, click Open next to Device Security.
  2. Select Settings in the Norton main window, then choose Firewall.
  3. Open the Program Control tab and check the program list for your application.
  4. Click Add to add the program manually.
  5. Complete the selection in the dialog box.
  6. Review the Security Alert and Norton’s recommended access setting before choosing the program’s access.

After you select the executable, Norton analyzes its reputation information and recommends an access setting in the Security Alert. Use the Info link to check the selected file’s location, or choose More Details to examine additional reputation information. Checking those details gives you information about the selected file before deciding how it should connect.

Create an Allow Rule in Smart Firewall

For the Add app rule workflow, open Norton and go to Advanced Security > Network > Smart Firewall. Choose Add app rule, define the parameters, set Action to Allow for the trusted application, and select Save. Available Action choices also include Smart mode, Block, and Ask, so make sure the saved action matches your intended access decision.

Existing application rules can be changed with the pencil icon rather than creating another rule. Modify the relevant parameters and select Save; the slider beside a rule turns it on or off without deleting it. Custom Program Control rules override Norton’s automatic rules for that program, making an application-specific change different from changing automatic access for all new programs. Even with an allow rule, Norton blocks infected programs attempting Internet access regardless of the Automatic Program Control setting.

Choose the Right Exception for the Block

Match the exception to what Norton is blocking: Program Control handles an application’s network access, Traffic Rules handle ports and connections, and separate controls cover sharing, blocked devices, scan detections, and website warnings. Choosing the right control keeps an application connection problem separate from a security detection that needs a different response.

Norton 360 Program Control manages Internet and network access for a named application. Traffic Rules instead match connection criteria such as protocol, direction, address, and local or remote port. Because Norton evaluates Traffic Rules before Program rules, an application set to Allow can still be affected by a traffic restriction.

Problem Matching Control Documented Location or Action
An application needs network access Program Control Settings > Firewall > Program Control, or the Smart Firewall application-rule controls
A port or connection needs permission Traffic Rules Smart Firewall > Traffic Rules > More > Create rule
File sharing, printer sharing, or Remote Desktop is blocked Public Network Exceptions Configure the relevant Windows service exception in Smart Firewall
Norton has blocked a device Blocked devices Smart Firewall > General > Additional settings > Manage devices > Unblock
A file or folder needs exclusion from scanning Antivirus exclusions Security > Scans > Open > Exclusions, or Security > Advanced Security > Computer > Antivirus > Exclusions
A website displays a Norton warning Safe Web Security > Advanced Security > Web > Safe Web; submit a trusted URL for analysis

Menu wording can differ by Norton product, interface, and platform, so treat these locations as documented routes rather than identical screens across installations. For example, the scan-exclusion controls appear under Scans in one interface and under Advanced Security > Computer > Antivirus in another. Both routes concern scanning, not permission for an application to communicate over a network.

Sharing problems belong with the network and service controls: Norton’s Public network defaults prevent Windows file sharing, printer sharing, and Remote Desktop from functioning without exceptions. Separately, a device that Norton has blocked after detecting a threat appears in Blocked devices. Removing that entry addresses the device block rather than creating permission for a particular executable.

Antivirus exclusions cause Norton to ignore selected files or folders during scans, which reduces protection. Before treating a suspected incorrect detection as an exclusion problem, Norton advises running LiveUpdate and then a Full Scan. An application firewall allow rule cannot override that detection.

Website warnings can come from Safe Web in the Norton app or browser extension, rather than Smart Firewall. If a blocked website is believed to be safe, Norton allows its URL to be submitted for analysis. Keep that review separate from firewall changes, and retain default firewall rules unless a specific change is necessary, since modifying or removing rules can impair firewall function and reduce security.

Review and Manage an Existing App Rule

Review an existing application in the program list, then select its rule’s pencil icon to change the settings and select Save. Use the slider beside a rule to enable or disable it without deleting it, or adjust its position to change its priority.

Each entry displays the program’s name, trust level, Internet usage, and network-access settings. Check that entry before creating another rule for the application. An automatically listed program does not necessarily need a custom exception: Smart Firewall generally creates appropriate access rules without user input.

Available Action settings are Smart mode, Allow, Block, and Ask. Smart mode lets Norton make access decisions automatically and normally avoids prompts, although unknown or untrusted programs may still trigger firewall alerts.

Allow permits access under the rule’s conditions, while Block denies it. Ask lets you choose access settings through firewall alerts. For a specific override, edit the relevant rule rather than changing Automatic Program Control to allow all Internet connections for new programs.

Because of that precedence, Norton recommends retaining Automatic Program Control in Smart Mode and modifying firewall rules only when absolutely necessary. Its warning is particularly relevant to users who are not advanced users: changing or removing rules can impair firewall functionality and reduce security.

Within each Program Rules entry, Norton processes rules from top to bottom, so a higher rule takes precedence over a lower one. Drag a rule’s row up or down to change that order. Traffic Rules are evaluated before Program Rules, which means an application-specific Allow rule may not determine the outcome when an earlier Traffic Rule applies.

Removal has two distinct scopes. Selecting a rule’s X icon and confirming removes that individual rule. To remove the application itself from Program Control instead, select App details, choose Remove app, and confirm. Disabling a rule with its slider leaves it available for later use.

Create Norton Traffic Rules for Ports and Connections

To create a port or connection exception, open Smart Firewall, select Traffic Rules, then choose More > Create rule, define the rule’s parameters, and select Save. Use this route for traffic identified by network criteria, such as protocol, address, direction, or port, rather than for permission tied to a particular application’s executable.

Choose Allow when the matching traffic should pass through the firewall, or Block when it should be denied. Available parameters include Name, Profile, Action, Protocol, Direction, Address, Local port, Remote port, and ICMP Type. Together, these controls let you define the traffic the exception covers instead of treating the change as a general application permission. Keep the rule focused on the connection requirement.

Protocol, Direction, and Address describe different parts of the traffic match, while Local port and Remote port provide separate port controls. Profile is another available parameter, alongside ICMP Type for rules that use that criterion.

Rather than copying an unrelated port example, define the parameters for the connection you intend to permit. Saving the rule completes Norton’s documented creation workflow. Custom Traffic Rules can later be edited, deleted, enabled, disabled, or reordered, allowing you to manage the exception separately from an application’s Program Control entry.

Rule order matters because Norton evaluates Traffic Rules before Program Rules. Higher Traffic Rules take precedence. An application allowed through Program Control can therefore remain unable to connect if a Traffic Rule blocks the port it uses. Check the traffic-level decision before assuming that another application allow rule will resolve the conflict.

Administrators in an older Spiceworks Community discussion reported preferring targeted port exceptions over zone-based trust when configuring remote-device inventory. Their advice addressed that particular administrative scenario, not a universal Norton recommendation. Treat that reported preference as context for choosing a focused traffic exception, while using Norton’s Traffic Rules > More > Create rule workflow rather than the discussion’s historical menu labels.

Before broadening an exception, consider both its matching criteria and its position in the Traffic Rules list. Moving a rule changes its priority, while editing its parameters changes which traffic it matches. Those are distinct adjustments: an Allow action alone does not explain the result without considering the traffic criteria and the rules evaluated ahead of it.

Allow Sharing or Review a Blocked Device

Use Public Network Exceptions when Norton’s firewall prevents Windows sharing services or Remote Desktop from working. For a device Norton has placed on its Blocked devices list, use Manage devices > Unblock to remove that block, confirming the action with OK.

On a Public network, Smart Firewall blocks file, folder, media, and printer sharing, along with Remote Desktop connections, by default. Norton recommends the Public setting for networks in places such as restaurants, malls, and airports. Those restrictions mean a sharing problem can involve the network’s protection settings rather than an individual application’s Internet access. Public Network Exceptions provide controls for permitting selected Windows services, and Norton says they can be configured for both Public and Private networks.

Available exceptions include incoming SMB file and printer sharing, incoming Remote Desktop connections, and printing notifications on public networks. Other options cover Internet Connection Sharing, incoming and outgoing ping and trace requests, DNS traffic, DHCP traffic, and VPN connections. These controls address particular services, so the relevant setting depends on the connection or sharing function involved. Selecting an exception for a Windows service is distinct from changing the network’s overall trust level.

Changing a network to Private has broader implications: it allows devices on that network to access the computer’s shared resources. Smart Firewall continues monitoring incoming traffic for known attacks and infections while the network is Private. Connected networks appear automatically on Norton’s Network tab, where each network can be designated Private or Public. Review that designation alongside the sharing settings, keeping the broader access granted by Private status in mind.

Within the General tab, find Additional settings and select Manage devices.

Locate the blocked device by its IP address, select Unblock beside it, and confirm with OK. Security History records Norton device-security activity relevant to troubleshooting firewall decisions, providing a place to review activity associated with connection problems and the firewall’s handling of them.

Keep Norton Antivirus Exclusions Separate from Firewall Rules

Adding a scan exclusion is therefore not the same as giving an application permission to connect, because firewall rules govern Internet and network access. Program Control is the feature for application network permissions; scan exclusions address scanning instead. Keep that distinction in mind before changing protection settings to resolve a blocked program or file.

Those are Norton’s recommended first steps when a legitimate file, program, or website appears to be flagged incorrectly; install all available definition updates before the Full Scan. Submitting a suspected false-positive file to Norton is another documented option: Norton says it analyzes submitted files and releases updated definitions addressing the detection within 48 hours.

For the scan-exclusion route through Scans, open Norton device security and select Security in the left pane. Next, select Open in the Scans tile and choose the Exclusions tab. Continue with the exclusion prompts. Menu paths can differ by Norton product, interface, and platform, so this route should not be treated as the universal layout for every Norton installation.

Another documented Windows route is Security > Advanced Security > Computer > Antivirus > Exclusions > Add. Select the file or folder and choose Save. Norton describes this route for situations where a business is affected, the user is certain the file is safe, or the user developed the file. Both routes concern antivirus exclusions rather than firewall access, even when the selected item is an application’s executable file.

Use an exclusion only for a specific need and when you are confident the item is not infected. Norton’s handling of infected programs still applies.

Check Why an Allowed App Still Cannot Connect

Check that the application’s Allow rule is enabled, then review its position and any Traffic Rules processed ahead of it. A website block or infected-program detection can also require a different response from changing the app’s network permissions.

Start in the program rule list and inspect the existing rule rather than adding another exception.

Review its parameters, including action, direction, profile, addresses, and ports, against the connection you intend to allow. Save any edits made through the pencil icon.

Next, examine the order of the application’s rules. Norton processes entries from top to bottom, with a higher rule taking precedence over a lower one. Drag a rule’s row up or down when its priority needs changing.

Traffic Rules require a separate check because Norton evaluates them before Program Rules. Even an enabled Allow rule cannot permit a connection if an earlier Traffic Rule blocks the port the application uses. Avoid treating an application exception as an override for every firewall decision.

Open Security History to review recorded Norton device-security activity relevant to the blocked connection. Those records can help with troubleshooting firewall decisions alongside the rule settings. If you need to reset Smart Firewall settings, select “Restore default settings.” Remember that Norton recommends modifying firewall rules only when absolutely necessary and warns that changes can impair firewall functionality and reduce security.

Consider Safe Web when the problem is access to a particular website.

Finally, distinguish permission to connect from a detection that the program is infected. Infected programs are blocked regardless of the Automatic Program Control setting. An Allow rule is therefore not a way to override that detection, and further firewall changes would address a different control from the one blocking the program.

Frequently Asked Questions

Why Does Norton Already List My App in Program Control?

Norton automatically adds a program to Program Control when it first attempts to connect to the Internet or a network. Program Control displays the program’s name, trust level, Internet usage, and network-access settings so you can review its access.

Does Adding an Executable Automatically Give It Allow Access?

Adding an executable prompts Norton to analyze its reputation and display a Security Alert with a recommended access setting. To explicitly allow a trusted application, create or edit its Program rule, set the Action to Allow, and select Save.

Why Can a Traffic Rule Block an App That Program Control Allows?

Traffic Rules are processed before Program rules, so a traffic-level block can determine the outcome before Norton evaluates the application’s Allow rule. If a Traffic Rule blocks a port the program uses, the application can be prevented from accessing the Internet despite its Program Control setting.

Do Norton Antivirus Exclusions Also Allow Network Access?

Antivirus scan exclusions tell Norton to ignore selected files or folders when scanning for security risks; they are not firewall access rules. Program Control governs an application’s Internet and network access. Norton warns that scan exclusions reduce protection and should be used only for a specific need when you are confident the item is not infected.

Can I Use a Firewall App Rule to Allow a Blocked Website?

Program Control manages an application’s network access, while Norton identifies Safe Web as a possible cause of website blocking. For a website you believe is safe, Norton recommends submitting the URL for analysis. Its website-access troubleshooting also includes turning Safe Web off and back on under Security > Advanced Security > Web > Safe Web.

Does Norton Require a Restart After Saving a Firewall Rule?

Norton’s documented application-rule workflow is to define or modify the rule’s parameters and select Save. To turn an application rule on or off without deleting it, use the slider next to that rule.

Match the exception to the task: use Program Control for an application’s network access, Traffic Rules for traffic defined by ports or other network criteria, and Public Network Exceptions for services such as sharing and Remote Desktop. Keep Automatic Program Control in Smart Mode unless a specific change is needed. Custom program rules override Norton’s automatic rules, and Traffic Rules take priority over Program rules, so review those controls before making further changes.

References

Sources read in September 2026.