Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 22 additions & 0 deletions docs/administrator-manual/security/threat_shield_ip.md
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,28 @@ Enterprise blocklists include a \"Confidence\" score which is shown in the UI. T

Yoroi and Nethesis blocklists are Enterprise blocklists. These lists will be listed only if the machine has a valid [Enterprise or Community subscription](../system/subscription.md) and a valid entitlement for the Threat Shield IP service.

### Nethesis community blocklist {#nethesis_community-section}

Attackers usually target many firewalls at once. NethSecurity and NethServer systems with a subscription share the attackers they block, so that each system can block them before they attack.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Attackers usually target many firewalls at once. NethSecurity and NethServer systems with a subscription share the attackers they block, so that each system can block them before they attack.
Attackers usually target many firewalls at once. NethSecurity and NethServer systems with a subscription share the IP addresses of the attackers they block, so every other system can block them before being targeted.


It works this way:

- When Threat Shield IP blocks an IP address with the [brute force protection](#brute_force-section), the firewall sends that address to Nethesis. Only public addresses are sent. The firewall sends them every 5 minutes.
- When enough systems report the same address, Nethesis adds it to the `Nethesis community - Level 2` blocklist.
- Firewalls with the Threat Shield add-on can enable this blocklist from the `Blocklist feeds` tab, like the other Enterprise blocklists. It is disabled by default.

Registered firewalls also apply the Nethesis global allowlist. The addresses in this list, such as the Nethesis subscription servers, are never blocked.

What happens depends on the subscription:

| Firewall | Sends blocked addresses | Nethesis global allowlist | `Nethesis community - Level 2` blocklist |
|---|---|---|---|
| Not registered | No | No | Not available |
| Registered | Yes | Yes | Not available |
| Registered with the Threat Shield add-on | Yes | Yes | Available, disabled by default |

No configuration is needed. Reporting starts when you register the firewall and stops when you unregister it. A firewall that is not registered sends nothing.

### Logging

The Threat Shield IP feature includes advanced logging capabilities to monitor and track potential threats. The logging section allows you to configure which types of blocked packets are logged:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,28 @@ Le liste di blocco Enterprise includono un punteggio "Affidabilità" mostrato ne

I blocklist di Yoroi e Nethesis sono blocklist Enterprise. Questi elenchi verranno visualizzati solo se la macchina ha un valido [abbonamento Enterprise o Community](../system/subscription.md) e un valido diritto per il servizio Threat Shield IP.

### Lista di blocco Nethesis community {#nethesis_community-section}

Gli attaccanti di solito colpiscono molti firewall contemporaneamente. I sistemi NethSecurity e NethServer con una sottoscrizione condividono gli attaccanti che bloccano, così ogni sistema può bloccarli prima che attacchino.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Gli attaccanti di solito colpiscono molti firewall contemporaneamente. I sistemi NethSecurity e NethServer con una sottoscrizione condividono gli attaccanti che bloccano, così ogni sistema può bloccarli prima che attacchino.
Gli attaccanti di solito colpiscono molti firewall contemporaneamente. I sistemi NethSecurity e NethServer con una sottoscrizione condividono gli indirizzi IP degli attaccanti che bloccano, così ogni altro sistema può bloccarli prima che attacchino.


Funziona così:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Funziona così:
Come funziona:


- Quando Threat Shield IP blocca un indirizzo IP con la [protezione brute force](#brute_force-section), il firewall invia quell'indirizzo a Nethesis. Vengono inviati solo indirizzi pubblici. Il firewall li invia ogni 5 minuti.
- Quando abbastanza sistemi segnalano lo stesso indirizzo, Nethesis lo aggiunge alla lista di blocco `Nethesis community - Level 2`.
- I firewall con l'add-on Threat Shield possono abilitare questa lista dalla scheda `Blocklist feeds`, come le altre liste di blocco Enterprise. È disabilitata di default.

I firewall registrati applicano anche la allowlist globale di Nethesis. Gli indirizzi in questa lista, come i server delle sottoscrizioni Nethesis, non vengono mai bloccati.

Il comportamento dipende dalla sottoscrizione:

| Firewall | Invia gli indirizzi bloccati | Allowlist globale Nethesis | Lista di blocco `Nethesis community - Level 2` |
|---|---|---|---|
| Non registrato | No | No | Non disponibile |
| Registrato | Sì | Sì | Non disponibile |
| Registrato con l'add-on Threat Shield | Sì | Sì | Disponibile, disabilitata di default |

Non serve alcuna configurazione. L'invio parte quando registri il firewall e si ferma quando annulli la registrazione. Un firewall non registrato non invia nulla.

### Registrazione

La funzione Threat Shield IP include funzionalità avanzate di registrazione per monitorare e tracciare le minacce potenziali. La sezione di registrazione consente di configurare quali tipi di pacchetti bloccati vengono registrati:
Expand Down
Loading