Device x is accessing malicious site y
I got a couple of alarms of category "Security Activity" in the form "Device x is accessing malicious site y". I followed up by blocking those domains, but I'd prefer the Firewalla to just block access to such domains by default. Is that possible?
My config:
- Active Protect: Enabled (Strict)
- Target lists used in block rules: OISD, DShield
-
Firewalla's system is based on reputation, and the reputation of activities and sites does change over time. Depending on the changes, an always-block policy will likely cause false positives and disturb your internet experience.
In your case, if only a warning happens, the problem may not be that bad, and the blocking is like introducing a false positive.
Strict mode will block more than the default mode
Please sign in to leave a comment.
Comments
2 comments