July 2020
July 17, 2020
Create Network groups from the subnets groups of the 'Observed' traffic
Create Network groups from a list of public and private subnet groups that assets communicate with, after Xshield has been upgraded to this version. After the upgrade, Xshield will list the subnet groups for all the Unauthorized, Authorized, and Blocked connections in your Xshield-managed network as ‘Observed’ public or private groups.
-
All such public subnets are listed in the /8 format and by the country of their origin, under the Observed Public Groups tab on the Network Groups page. The Reputation column on the Network Groups page displays the historical threat reputation of the subnet group. The threat reputation for subnet groups is derived from Xshield’s threat reputation intelligence engine.
-
All such private subnets are listed in the /24 format, under the Observed Private Groups tab on the Network Groups page.
Select One or more public or private subnets under these tabs and create new a Network group or add the subnets to an existing Network group.
See Network groups for more details.
July 2, 2020
Filter traffic flows by their geographical locations on Flow Explorer
On the Information Center > Flow Explorer page, use the Advanced Filter to filter traffic flows by the countries or cities from where the flows originate or result.
Filter by a country to see traffic flows from or to the cities in the country.
Delete entries of non-essential Suspended assets
On the Account Settings page, enable the Delete Cloud AutoScale Suspended Assets setting. Specify a unique Environment tag that Xshield must look for(on Suspended assets), to consider deletion, and the time after which these Suspended assets' entries must be deleted from the Assets page.
You must tag the non-essential and potential non-essential assets with the unique ENVIRONMENT tag in One of the following ways - from the Xshield UI, at the time of agent installing agents from the CLI or at scale, or by tuning the auto-scaler configuration on the third-party cloud to add the unique tag to the scaled-up assets.
This setting only works for assets that are managed using Xshield agents.