SDWAN Intrusion Prevention Policy

A security feature designed to detect and block known network attacks by leveraging predefined rules and signature.

Table 1. Intrusion Prevention Policy

Field

Description

Object Name

Name of the intrusion prevention policy.

Signature Set

Choose a signature set that defines the rules for evaluating traffic from the Signature Set drop-down list.

Inspection Mode

Choose the inspection mode.

Custom Signature Set:

Select one or more web categories from the drop-down list.

Custom signature must be enabled from Catalyst SD-WAN Manager under Administration > Settings > External Services > UTD Snort Subscribe Signature.

Signature Allow List

Select a signature allow list.

Alerts Log Level

Choose the alert log level.

This refers to the severity levels of logs generated by the system, which can be configured to control the granularity of information logged.