Assign security connectors to a policy
An SIA administrator creates a policy to define how their company handles known or suspected threats, as well as violations of an acceptable use policy.
To direct malicious traffic to the security connector when it's used as a DNS sinkhole, in a policy configuration, select the Block policy action and the Error Page response. You can then assign Security Connector to a category or list.
As a best practice, assign a security connector to the malware and C&C categories. A C&C threat indicates that a user's machine is already compromised by the time it's detected. To clean compromised machines, you can use Security Connector to identify infected machines and get the information you need for remediation.
To assign security connectors to a policy:
-
In the Threat Protection menu of Enterprise Center, select Policies > Policies.
-
On the Policies page, click the plus sign.
-
Enter a name and description for the policy.
-
To configure a policy with settings from a predefined template, select one of these templates and click Continue:
-
Strict. Contains settings that block known and most suspected threat categories. Select this template to apply settings that are a best practice for a policy.
-
Monitor-only. Logs and reports threats but it does not block them. This template is ideal for testing or assessing policy impact before using the Strict template. This template assigns the monitor policy action to all known and suspected threat categories.
-
Custom. Lets you define policy actions for known and suspected threats.
-
-
To assign a location or sub-location, click the link icon for locations or sub-locations, and select one or more. Then click Associate.
-
Configure policy settings in the Settings tab. To enable SIA Proxy, see Set up SIA Proxy.
-
To assign a security connector to a threat category or a custom list:
-
In the threat or the Custom List tab, select the Block action for a threat category or list. If you applied the Strict policy template, you may not need to perform this step.
-
In the Response to User menu, select Error Page. If you applied the Strict policy template, you may not need to perform this step.
-
In the Security Connector menu, select a security connector. To support HTTP or HTTPS traffic, make sure you upgrade security connector to version 2.5.0 or later.
-
Repeat steps 7a to 7c to assign a security connector to other categories or lists.
-
-
To enable alerts, toggle the Send Alert option to on.
-
Click Save. If you want to save and deploy the policy, click Save and Deploy.
Next steps
-
If you haven’t deployed the policy, make sure you deploy it to the SIA network. For instructions, see Deploy configuration changes.
-
Add email addresses for Security Connector upgrade notifications.
Updated over 1 year ago