Configuring Network Attack Blocker settings

25 March 2022

ID 67228

To configure the Network Attack Blocker settings:

  1. Open the Administration Console of Kaspersky Security Center.
  2. In the console tree, perform one of the following actions:
    • If you want to configure the operating settings of SVMs of one KSC cluster, in the Managed devices folder of the console tree select the administration group containing the KSC cluster.
    • If you want to configure the operating settings of SVMs of all KSC clusters, select the Managed devices folder.
  3. In the workspace, select the Policies tab.
  4. Select a policy in the list of policies and double-click the policy to open the Properties: <Policy name> window.
  5. In the policy properties window, select the Intrusion Prevention section.
  6. Select an action in the Action upon detecting network attack list.

    If network protection is deployed in monitoring mode, the Ignore action is applied when a network attack is detected, regardless of the selected action.

  7. If required, change the value of the setting On detection of a network attack or suspicious network activity, block traffic from IP address for N minutes.
  8. If necessary, configure network threat protection exclusion rules that Kaspersky Security will use to exclude traffic of specific IP addresses from scans or apply special actions when processing such traffic.
  9. In the Properties: <Policy name> window, click OK.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.