Blocked Default Threats Report
Applies To: Cloud-managed Fireboxes, Locally-managed Fireboxes
The Blocked Default Threats report shows statistics for connections dropped due to these Default Threat Protection settings on the Firebox:
- Default Packet Handling
- Blocked Sites
- Blocked Ports
This report is available when log messages with data for this report exist in the specified time frame. To make sure that your Firebox sends log messages required to generate this report, follow the steps to Enable Logging for this Report.
How to Use this Report
This report can help you to visualize the number and proportion of threats blocked by the Default Threat Prevention settings on the Firebox over the selected time period. Here are some ways to use this report:
- Monitor the statistics to identify possible attacks on your network.
View the Report
This report is available in WatchGuard Cloud and in Dimension.
- Log in to WatchGuard Cloud.
- Select Monitor > Devices.
- Select a folder or a specific device.
- To select the report date range, click .
- From the list of reports, select Device > Blocked Default Threats
The report opens.
- To see reports for your Fireboxes or FireClusters, select Home > Devices.
The Devices list opens.
To see reports for your groups of Fireboxes, select Home > Groups.
The Groups list opens. - Select the Name of a Firebox, cluster, or group.
The Tools > Executive Dashboard page opens. - Select the Reports tab.
- Select Device > Blocked Default Threats.
The report opens.
The Blocked Default Threats report includes a row for each type of threat that can be blocked by Default Packet Handling options configured on the Firebox.
Column | Description |
---|---|
Blocked Default Threats | Type of threat that was blocked Each type corresponds to a setting in the Default Threat Protection settings on the Firebox |
Denied Hits | Number of denied hits |
Hits% | Percentage of hits |
Enable Logging for this Report
Logging for all Default Threat Protection features is enabled by default for locally-managed Fireboxes.
The Firebox always sends a log message when it blocks Default Packet Handling message when the Firebox blocks dangerous activities. To collect the data required to show statistics about blocked sites and blocked ports in this report, in the Blocked Sites and Blocked Ports settings for Logging, select Send a log message.