Norton Firewall: Per User Rule Sets + Hidden Rule Ordering Break LAN Apps (Ditto Example)

Note: Please do not post Personally Identifiable Information like email address, personal phone number, physical home address, product key etc.

Issue abstract:Norton 360’s firewall has several undocumented behaviors that make LAN applications unreliable unless users understand hidden rule‑ordering logic and per‑profile rule separation. These issues caused Ditto (a LAN clipboard manager) to fail silently on one Windows account while working on another, even though both accounts were on the same PC and the same network.

Detailed description:

Product & version number:26.7.11086 (build 26.7.11086.990)

OS details:Windows 11 v 25H2

What is the error message you are seeing?

If you have any supporting screenshots, please add them:

1 Like

Key Problems Identified

1. Firewall rules are stored per Windows user, not globally

Norton does not document this anywhere. This means:

  • Each Windows account has its own separate firewall rule list

  • A rule created under one account does not apply to others

  • LAN apps may work under one user but fail under another

  • Troubleshooting becomes extremely confusing

2. Running Norton “as Administrator” loads the Admin’s firewall profile, not the current user’s

If a standard user launches Norton with “Run as administrator,” Norton silently switches to the Admin firewall rule set. This leads to:

  • Users believing they are editing their own rules when they are not

  • Rules appearing to exist but not actually applying

  • LAN apps failing despite seemingly correct rules

This behavior is extremely misleading.

3. Norton’s Traffic Rules list is unsorted, ungrouped, and unfilterable

The list often contains hundreds of auto‑generated rules. There is:

  • No sorting by name

  • No grouping by program

  • No way to filter by application

  • No way to see recently added rules

  • No way to identify which rules apply to LAN traffic

This makes rule management nearly impossible.

4. Norton inserts global inbound Block rules high in the list

Modern Norton versions add rules such as:

  • “Block all other traffic”

  • “Block inbound traffic”

  • “Block suspicious inbound connections”

These rules appear above user‑created Allow rules.

Because Norton evaluates rules top‑to‑bottom, these Block rules override everything below them, silently breaking LAN applications unless users manually drag their Allow rules above the Block rules.

This behavior is not documented and not intuitive.

5. LAN apps that worked for years suddenly break after Norton updates

Older Norton versions:

  • Trusted LAN traffic

  • Auto‑allowed Ditto

  • Had fewer Block rules

  • Used global rule sets

Newer versions:

  • Treat LAN traffic as suspicious

  • Add aggressive Block rules

  • Enforce strict rule ordering

  • Store rules per‑user

This causes LAN apps to fail without warning.

Real‑World Example: Ditto Clipboard Manager

Ditto uses a simple TCP/UDP listener on port 2345 for LAN clipboard sharing.

Symptoms observed:

  • Ditto worked under the Admin account

  • Ditto failed under a standard user account

  • The inbound rule appeared to exist, but Norton was loading the wrong profile

  • The rule was buried under Block rules

  • Dragging the rule above the Block rules fixed the issue immediately

This behavior is extremely difficult for average users to diagnose.

Requested Improvements

  1. Document that firewall rules are per‑Windows‑user

  2. Warn users when Norton loads a different profile due to elevation

  3. Provide sorting and filtering in Traffic Rules

  4. Group rules by application

  5. Allow users to mark rules as “global for all Windows accounts”

  6. Prevent Norton updates from inserting Block rules above user‑created Allow rules

  7. Provide a “LAN trusted zone” option for local subnet traffic

These changes would make Norton’s firewall far more predictable and user‑friendly.