Configure network protection settings Skip Navigation

Configure network protection settings

You can use intrusion protection to enable deep network threat detection using network connection signatures. Intrusion protection is enabled by default. When intrusion protection is enabled,
CylanceGATEWAY
logs and automatically blocks connections when a threat is detected. When intrusion protection is disabled, threats are logged but the connection is not blocked.
You can use destination reputation to block potentially malicious IP addresses and FQDNs that match a set risk level threshold (low, medium, or high). Destination reputation is disabled by default. When enabled, the default risk level is high and
CylanceGATEWAY
logs and automatically blocks connections to the destinations that match the set risk level. When destination protection is disabled, threats are logged but the connection is not blocked.
You can also configure
CylanceGATEWAY
to display a message to users whenever
CylanceGATEWAY
blocks a connection to a potentially malicious destination.
  1. On the menu bar, click
    Settings > Network
    .
  2. Click the
    Network Protection
    tab.
  3. If you want users to see a message when
    CylanceGATEWAY
    blocks a connection, select
    Display a blocked notification message on devices
    .
  4. In the
    Message
    field, type the message that you want to display to users.
  5. To turn on intrusion protection, select
    Enable intrusion protection
    .
  6. To turn on destination reputation, select
    Enable destination reputation
    and select the minimum risk level for potentially malicious IP addresses to block.
  7. Click
    Save
    .