Skip to main content

Tutorial: Protect Your Users From Malware and Other Cyber Threats

Abstract

Learn how to protect CloudConnexa users from malware, ransomware, and cyber threats using Cyber Shield — configure Domain Filtering and Traffic Filtering (IDS/IPS) per Shield Policy, set content category blocking, and use Allow and Block Lists for different User Groups.

Overview

Use CloudConnexa Cyber Shield to protect users from malicious domains and network threats. You can apply different protection settings per User Group with Shield Policies, allowing you to tailor security and content filtering for each group.

In this tutorial, you will:

  • Configure baseline protection with the Default Policy.

  • Create a custom Shield Policy for a User Group that needs different filtering.

  • Block unwanted content categories and specific domains.

  • Configure Traffic Filtering to detect or block threats such as malware and ransomware.

  • Use the Top 10 Dashboard to investigate Cyber Shield events.

This tutorial focuses on protecting users after you've connected them to CloudConnexa. For an introduction to Cyber Shield and its filtering features, refer to About Cyber Shield.

Before you begin

You need:

Tip

Shield Policies let you apply different Domain Filtering and Traffic Filtering settings to different User Groups. Each User Group uses one Shield Policy.

Your WPC already has a Default Policy. User Groups not assigned to a custom Shield Policy use the Default Policy, so configure it first to establish your baseline protection.

For more information about how policies apply, refer to About Shield Policies and About the Default Policy.

Start by configuring the protection you want to apply to User Groups that don't require their own custom Shield Policy.

  1. Select Shield → Policies.

  2. Select the edit icon for Default Policy.

  3. Select the Domain Filtering tab.

  4. Turn on Domain Filtering.

  5. Select a protection level:

    • Monitor Only

    • Basic Protection

    • Safe Browsing

    • High Productivity

    • Custom

  6. If you select Custom, configure the individual categories you want to monitor or block.

  7. Save your changes.

    • The Default Policy now provides your baseline Domain Filtering configuration.

      Note

      Domain Filtering applies only to DNS queries resolved through CloudConnexa. DNS Proxy must be on for Domain Filtering to apply. Encrypted DNS, such as DNS over HTTPS (DoH), can bypass Domain Filtering when DNS queries use another resolver.

For details about the available protection levels and categories, refer to Domain Filtering Protection Levels and Content Categories.

If a User Group needs different protection from the Default Policy, create a custom Shield Policy.

For example, you might use different policies for employees, contractors, students, guests, or other groups with different security or acceptable-use requirements.

  1. Select Shield → Policies.

  2. Select New Policy.

  3. Enter a unique policy name.

  4. Enter an optional description.

  5. Assign the User Groups that should use the policy.

  6. Select the Domain Filtering tab.

  7. Turn on Domain Filtering.

  8. Select a protection level or configure individual content categories.

  9. Save the policy.

    • The assigned User Groups now use the custom Shield Policy instead of the Default Policy.

Tip

You can assign multiple User Groups to the same policy, but each User Group uses only one Shield Policy. For users who belong to multiple groups, CloudConnexa applies the policy assigned to their primary User Group.

For more information, refer to Create or Edit a Shield Policy and Assign User Groups to a Shield Policy.

Content categories provide broad filtering, but you can also control access to specific domains per Shield Policy.

Use the:

  • Domain Allow List to allow a domain even when its content category is blocked.

  • Domain Block List to block a domain regardless of its content-category settings.

Allow a specific domain

  1. Open the Shield Policy.

  2. Select the Domain Allow List tab.

  3. Turn on Enable Allow List.

  4. Enter the domain you want to allow.

  5. Save your changes.

Block a specific domain

  1. Open the Shield Policy.

  2. Select the Domain Block List tab.

  3. Turn on Enable Block List.

  4. Enter the domain you want to block.

  5. Save your changes.

Tip

You can also upload .txt files for larger Allow Lists or Block Lists.

For domain-matching behavior, batch uploads, comments, and list limits, refer to Override Blocked Domains with a Domain Allow List and Block Access to Specific Domain Names with a Block List.

Domain Filtering protects users based on the domains they access. Traffic Filtering examines tunneled network traffic for threat signatures.

Traffic Filtering can operate as an Intrusion Detection System (IDS)/Intrusion Prevention System (IPS). Configure it to monitor threats or block matching traffic based on threat priority or category.

  1. Select Shield → Policies.

  2. Select the edit icon for the Shield Policy you want to configure.

  3. Select the Traffic Filtering tab.

  4. Turn on Traffic Filtering.

  5. Choose how to configure protection:

    • Per Priority: Configure protection based on Critical, High, and Medium threat priorities.

    • Per Category: Select individual threat categories.

  6. Configure the threats you want to monitor or block.

  7. Save your changes.

For example, Traffic Filtering includes threat categories such as Malware and Ransomware and Intrusion Activity.

Repeat this configuration for other Shield Policies that require Traffic Filtering.

For the complete options, refer to Traffic Filtering Priorities, Categories, and Protection Levels.

After creating your policies, verify that your User Groups have the intended protection.

  1. Select Shield → Policies.

  2. Review the policies under All Policies.

  3. Verify the Domain Filtering and Traffic Filtering status for each policy.

  4. Review the number of User Groups assigned to each custom policy.

  5. Select the User Group count when you need to review the assigned groups.

Note

Any User Group that isn't assigned to a custom policy continues to use the Default Policy.

For more information about reviewing your configuration, refer to Browse and Manage Shield Policies.

Use the Top 10 Dashboard to identify the Domain Filtering and Traffic Filtering categories generating the most events.

  1. Select Shield → Overview.

  2. Locate the Top 10 Dashboard.

  3. Select a Period.

  4. Select Domain or Traffic for Filtering Type.

  5. Select Monitored or Blocked for Events.

  6. Review the Top 10 categories by event count.

  7. Select a category to drill down and identify the sources generating those events.

  8. Continue drilling down as needed to investigate affected users and devices.

  9. Use View All to continue the investigation in Shield → Metrics with the selected period and filters.

For detailed instructions, refer to Interact with the Cyber Shield Top 10 Dashboard and Investigate Using Cyber Shield Top 10 Dashboard.

What happens next

Your users now receive Cyber Shield protection based on their User Group's Shield Policy.

You can:

  • Use the Default Policy as baseline protection.

  • Create custom policies for User Groups that need different Domain Filtering or Traffic Filtering.

  • Use Domain Allow Lists and Block Lists for specific domain exceptions.

  • Review the Top 10 Dashboard and Cyber Shield Metrics to identify and investigate filtering events.

  • Update User Group assignments as your security requirements change.