Editing the settings used in blocking an attacking device

January 10, 2024

ID 65696

Network traffic from the attacking device is blocked for one hour. You can edit the settings for blocking an attacking device.

To edit the settings for blocking an attacking device in Kaspersky Security Center:

  1. Open Kaspersky Security Center Administration Console.
  2. In the Managed devices folder of the console tree, open the folder with the name of the administration group to which the relevant protected virtual machines belong.
  3. In the workspace, select the Policies tab.
  4. Select a Light Agent for Windows policy in the list of policies and open the Properties: <Policy name> by double-clicking.
  5. In the policy properties window, select the Network Attack Blocker section in the list on the left.
  6. In the right part of the window, in the Network Attack Blocker settings section:
    • Select the Add the attacking device to the list of blocked devices for N min check box if you want the Network Attack Blocker component to block the network activity of an attacking device for a specified amount of time, thereby automatically protecting the virtual machine against possible future attacks from this address. In the field on the right, specify the amount of time to block an attacking device.

      By default, network traffic from the attacking device is blocked for one hour.

    • Clear the Add the attacking computer to the list of blocked computers for N min check box if you do not want the Network Attack Blocker component to enable automatic protection against possible future network attacks from this address.
  7. Click the Apply button.

To edit the settings for blocking an attacking device in the local interface:

  1. On the protected virtual machine, open the application settings window.
  2. In the left part of the window, under Anti-Virus protection, select Network Attack Blocker.

    The Network Attack Blocker settings are displayed in the right part of the window.

  3. Do the following:
    • Select the Add the attacking device to the list of blocked devices for N min check box if you want the Network Attack Blocker component to block the network activity of an attacking device for a specified amount of time, thereby automatically protecting the virtual machine against possible future attacks from this address. In the field on the right, specify the amount of time to block an attacking device.

      By default, network traffic from the attacking device is blocked for one hour.

    • Clear the Add the attacking computer to the list of blocked computers for N min checkbox if you do not want the Network Attack Blocker component to enable automatic protection against possible future network attacks from this address.

    If the settings in the local interface are not available, this means that the values of settings defined by the policy are used for all protected virtual machines of the administration group.

  4. To save changes, click the Save button. 

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.