Malicious Inventory-Based Filter
By default, the feature to identify well-known malicious IP addresses is disabled. Once enabled, you can identify all well-known malicious IPv4 addresses using the Malicious inventories filter. You can use this read-only filter to create and enforce policies on workloads to block communication between workloads and well-known malicious IPv4 addresses.
By default, the query for the Malicious inventories filter is set to * Is_malicious = true
.
For more information on the following topics, refer to the corresponding sections:
-
To enable detection of malicious consumer and provider IP addresses, see Visibility of Well-Known Malicious IPv4 Addresses.
-
To create microsegmentation policies, see Create and Discover Policies.
-
To enforce policies on your workloads, see Enforce Policies.