Global and domain security intelligence lists
A security intelligence list helps you manage firewall policies by
-
lets you manage lists of connections to block or exempt,
-
applies your policies consistently across global and domain contexts, and
-
enables further threat evaluation without the need to redeploy firewall policies.
Security intelligence list reference information
The Cloud-Delivered Firewall Management Center includes Global Block and Do Not Block lists, so you can use Security Intelligence to consistently block or exempt connections, allowing evaluation by other threat detection processes you configure.
Access control and DNS policies use these Global lists by default, and they apply to all security zones. If you want, you can turn these lists off for individual policies.
-
Global Block list: Lets you block specified connections in all security zones.
-
Do-Not-Block list: Lets you exempt specified connections from blocking so you can further evaluate threats.
Note | These options apply only to Security Intelligence. Security Intelligence does not block traffic already fastpathed. Adding an item to a Security Intelligence Do Not Block list does not mean matching traffic is trusted or fastpathed. For more information, see Security intelligence. |
Global and domain security intelligence lists example
For example, if you notice a set of routable IP addresses in intrusion events associated with exploit attempts, you can immediately block those IP addresses. Although it may take a few minutes for your changes to propagate, you do not have to redeploy.