Skip to main content
This section provides the purpose, elements, and actions performed on the Distributed Cloud Firewall pages.

Purpose

The Overview sub-tab provides a summary of threat activity, egress traffic, and firewall coverage detected by the Distributed Cloud Firewall.

Elements

Distributed Cloud Firewall Dashboard Overview
  • Filters panel: Filters the dashboard by Time Period (with Start and End date/time), VPC/VNet, and Direction.
  • Threat Overview: A zoomable map showing the geographic origin and destination of detected threats.
  • Security Control card: Displays Monitored Rules and Protected Rules counts, with a Manage Security Control button.
  • Egress Security Score card: Displays an aggregate egress security score, with a Manage VPC/VNets button.
  • Total Threats card: Displays Logged and Denied counts.
  • Unique Threat IPs card: Displays Logged and Denied counts.
  • Geo-Traffic card: Displays Logged and Denied counts.
  • SaaS Services panel: Per-service toggle buttons (for example, Azure, GitHub) showing traffic for the selected service.
  • Intrusions table: Displays intrusion counts by severity, with a View All button.

Actions

To filter the Dashboard based on time or VPC/VNet:
  1. In the Filters panel, select a Time Period, or set a custom Start and End date and time.
  2. Select a VPC/VNet and a traffic Direction to narrow the dashboard to a specific scope.
The Dashboard updates to reflect the selected time period and scope.
To review the geographic origin and destination of detected threats:
  1. Review the Threat Overview map for the geographic origin and destination of detected threats.
  2. Use the zoom in, zoom out, and reset view controls to adjust the map view.
To review coverage and egress security posture summaries:
  1. Review the Monitored Rules and Protected Rules counts on the Security Control card, or select Manage Security Control to go to the Security Control sub-tab.
  2. Review the Egress Security Score card for an aggregate score representing the security posture of egress traffic, or select Manage VPC/VNets to scope the score to specific VPCs or VNets.
To review threat and traffic summary counts:
  1. Review the Logged and Denied counts on the Total Threats and Unique Threat IPs cards for the selected time range.
  2. Review the Logged and Denied counts on the Geo-Traffic card. On the SaaS Services panel, select a service button (for example, Azure or GitHub) to view traffic for that service.
To review intrusion counts by severity:
  1. Review the Intrusions table for a count of intrusions by severity.
  2. Select View All to open the full list of intrusion detection events.

Parameter Details

To review detected threats and their activity over time:
  1. Review the Identified Threats panel for a breakdown of threats by category and severity.
  2. Review the Threats Activities panel for a timeline of threat detections over the selected time range.