Creating a network isolation rule while viewing information about a network event

To create a network isolation rule while viewing information about a network event

  1. Select the Network traffic events section in the application web interface window.
  2. Select the event for which you want to view information.
  3. Click the Threat response button.
  4. Select Device network isolation.

    This opens the New rule window.

  5. In the Connector name drop-down list, select the name of the solution that you want to use to isolate the device.

    For this solution, a connector must have been created for integration with NGFW solutions. Users need the Administrator role to be able to create a connector.

  6. In the Device IP drop-down list, select the IP address of the device that you want to isolate.
  7. Click Run.
  8. In the confirmation window, select Yes.

The network isolation rule is created.

After creating the rule, Kaspersky Anti Targeted Attack Platform sends a request to enact the network isolation of the device to the NGFW solution that you selected when creating this rule.

Page top