AI Prevent Status
AI Prevent Status
Click on AI Prevent from the navigation bar.
Select AI Prevent Status.
AI Prevent Status displays the currently blocked hosts, including source hosts or target hosts. A source host is the device or system that initiates network traffic. A target host is the device or system that receives network traffic.
The hosts are listed by IP and MAC address. An IP address identifies a device on the network, and a MAC address identifies the device's hardware.
Click any row to view the details and the root cause of the blockage in "Details". To delete rules, select any blocked address and click "Delete Selected."
AI Prevent Configuration
To access AI Prevent Configuration,
Click on AI Prevent from the navigation bar.
Select AI Prevent Configuration.
Triggers
Triggers are events that cause AI Prevent to block a device. They allow you to control which notifications are generated.
In Triggers, Type is the Notification, and Match Criteria is the Notification category, for example, Address scan detected. Under Actions, enable or disable any notifications.
SDN Controller Settings
An SDN (Software-Defined Networking) controller manages network devices and traffic flows. NDR integrates with SDN controllers to automatically block or allow traffic based on detections.
In Integration Settings, set up the controller type (including SDN controllers, OpenDaylight, and UniFi) and the TCP Reset method.
Click the drop-down under Controller Type.
Select either ODL, UniFi SDN, or TCP Reset.
ODL (OpenDaylight):
OpenDaylight (ODL) uses open protocols to provide centralized, programmatic control over network devices.
Enter the Address and Port.
Specify the protocol, table ID, and node ID.
In Authentication, select TLS and Verify Certificate. You must check TLS before selecting Verify Certificate.
Enter your username and password.
Select Test to check the SDN controller connection.
Click Save.
UniFi SDN:
UniFi SDN manages UniFi devices, providing a user-friendly interface for configuring and monitoring switches, access points, and gateways.
Enter the Address and Port.
In Authentication, select TLS and Verify Certificate. You must check TLS before selecting Verify Certificate.
Enter your username and password.
Select Test to check the SDN controller connection.
Click Save.
TCP Reset:
TCP Reset terminates suspicious connections by sending TCP reset (RST) packets, abruptly closing the connection between two devices and prompting the sender to retry.
Test the SDN controller connection.
Click Save.
Last updated
Was this helpful?