Skip to main content

Select Malicious Traffic To Block Based on Threat Priority Levels

Abstract

Configure Traffic Filtering in a CloudConnexa Shield Policy to block malicious traffic by threat severity — choose to block Critical only, Critical and High, or Critical, High, and Medium threat priority levels using the Per Priority mode.

Overview

Configure Traffic Filtering per Shield Policy to block malicious traffic based on threat severity. On the policy's Traffic Filtering tab, select Per Priority to apply an Intrusion Prevention System (IPS) protection level based on the priority assigned to matching threat signatures.

Threat signatures are classified as Critical, High, or Medium. The protection level you select determines which threat priorities CloudConnexa blocks.

For more information about how Shield Policies apply filtering settings, refer to About Shield Policies.

For details about Traffic Filtering priorities and protection levels, refer to Traffic Filtering.

Before you begin

Ensure you have a Shield Policy to configure.

You can configure the Default Policy or a custom Shield Policy. To create a custom policy, refer to Create or Edit a Shield Policy.

Block malicious traffic by threat priority

  1. Navigate to Shield → Policies.

  2. Select the Edit policy icon for the Shield Policy you want to configure or select New Policy.

  3. Select Traffic Filtering.

  4. Turn on Traffic Filtering.

  5. Select Per Priority.

  6. Select the protection level you want to apply:

    Protection Level

    Behavior

    Monitor Only (IDS)

    Monitors matching traffic without blocking it.

    Critical (IPS)

    Monitors matching traffic and blocks threats with a Critical priority.

    Critical and High (IPS)

    Monitors matching traffic and blocks threats with Critical or High priority.

    Critical, High, and Medium (IPS)

    Monitors matching traffic and blocks threats with Critical, High, or Medium priority.

  7. Save your changes.

    • The selected Traffic Filtering settings apply to traffic protected by that Shield Policy.

What happens next

CloudConnexa monitors tunneled traffic for matching threat signatures. When a match has a priority included in your selected Per Priority protection level, the IPS blocks the matching traffic.

To block traffic based on specific threat types rather than threat severity, refer to Block Threat Categories.