Configuring the Policy for Cloud One Network Security


1. Sign in to the Cloud One

  • Select the Network Security tile
  • Expand Policy
  • Click on Intrusion Prevention Filtering

ns_policy1


Here you will see all the available filters. As you can see we have more than 22k filters that can be applied.

  • You can use the Search filters by properties text box to search for specific filters.

ns_policy1


2. Apply the following IPS filters.

2.1 Search for the filter: 5673

5673: HTTP: SQL Injection (Boolean Identity)

  • Check the rule box to assign
  • Click the Settings Wheel to configure rule
  • Use customized actions
  • Filter State: Enabled
  • Flow Control: Permit
  • Log Event: Enabled
  • Save

ns_ips


2.2 Search for the filter: 3798

3798: HTTP: SQL Injection (Boolean Identity)

  • Check the rule box to assign
  • Click the Settings Wheel to configure rule
  • Use customized actions
  • Filter State: Enabled
  • Flow Control: Permit
  • Log Event: Enabled
  • Save

ns_ips


2.3 Search for the filter: 0361

0361: HTTP: Protected File Access (/etc/passwd)

  • Check the rule box to assign
  • Click the Settings Wheel to configure rule
  • Use customized actions
  • Filter State: Enabled
  • Flow Control: Block
  • Log Event: Enabled
  • Save

ns_ips


2.4 Search for the filter: 6763

6763: HTTP: Wget Web Page Retrieval Attempt

  • Check the rule box to assign
  • Click the Settings Wheel to configure rule
  • Use customized actions
  • Filter State: Enabled
  • Flow Control: Block
  • Log Event: Enabled
  • Save

ns_ips


Congrats you have assigned filters for your Network Security Appliance policy. Next you will distribute the policy and validate protection. 🤩 🤖 ✅ ☁️