The Network Protection > Firewall tab presents comprehensive data about the firewall activity, classified according to source IP, source hosts, number of received packets and number of services.
Note – Packets with a TTL less than or equal to one are dropped without being logged.
From the first drop-down list, select the type of data to display, e.g., Top Source Hosts or Top Services By Destination. Select the desired entry, and, if an additional box is displayed, specify the respective filter argument. Additionally, using the drop-down list below, you can filter the entries by time. Always click Update to apply the filters.
On the By Source and By Destination views you can manually provide an IP/Network, as well as network ranges (e.g., 192.168.1.0/24 or 10/8). On the By Service views you can enter protocol and service, separated by comma (e.g., TCP,SMTP or UDP,6000).
On the Top Source Hosts and Top Destination Hosts views, if you click an IP or a hostname in the result table, it will automatically be used as a filter for the Top Services By Source or Top Services By Destination view. On the Top Services view, if you click a service in the result table, it will automatically be used as a filter for the Top Source Host By Services view.
By default, 20 entries per page are displayed. If there are more entries, you can jump forward and backward using the Forward and Backward icons, respectively. In the Number of rows drop-down list, you can increase the number of entries displayed per page.
You can download the data in PDF or Excel format by clicking one of the corresponding icons in the top right corner of the tab. The report is generated from the current view you have selected. Additionally, by clicking the Pie Chart icon—if present—you can get a pie chart displayed above the table.