Procedure
- Go to .
- Click Add.A new screen appears.
- Select Enable.
- Specify the rule priority.
- (Optional) Type a Description.
- Type one or more IP addresses, or IP address ranges.
Note
Only packets for detections of the specified addresses or within the specified ranges are captured.You can add a maximum of 50 entries that can be IP addresses or IP address ranges. - In Detection Criteria, do nothing to apply the rule to any detection, or click add specific criteria.
- If you clicked add specific criteria, specify the
criteria.
-
Detection Type
-
Detection Rule ID
-
Threat/Detection/Reference
Note
Contains and Does not contain match partial strings. Equals does not match partial strings. -
Severity
Note
Click "+" to add additional criteria. Alternatively, click "-" to remove criteria.You can add a maximum of 10 criteria. -
- Select the action to perform when packets match the criteria.
- Capture
- Do not capture
- Click Add.