> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Distributed Cloud Firewall

> This section provides the purpose, elements, and actions performed on the Distributed Cloud Firewall pages.

This section provides the purpose, elements, and actions performed on the
**Distributed Cloud Firewall** pages.

<Tabs>
  <Tab title="Dashboard">
    <Tabs>
      <Tab title="Overview">
        ## Purpose

        The **Overview** sub-tab provides a summary of threat activity, egress traffic, and firewall coverage detected by the Distributed Cloud Firewall.

        ## Elements

        <Frame>
          <img src="https://mintcdn.com/aviatrix-14b37c43/G_ugohXUfLjeuLC7/images/reference/ui/security/dcf-dashboard-overview.png?fit=max&auto=format&n=G_ugohXUfLjeuLC7&q=85&s=d130c3430ea0cdf09b34e17f88f400d0" alt="Distributed Cloud Firewall Dashboard Overview" width="100%" data-path="images/reference/ui/security/dcf-dashboard-overview.png" />
        </Frame>

        * **Filters panel**: Filters the dashboard by **Time Period** (with **Start** and **End** date/time), **VPC/VNet**, and **Direction**.
        * **Threat Overview**: A zoomable map showing the geographic origin and destination of detected threats.
        * **Security Control** card: Displays **Monitored Rules** and **Protected Rules** counts, with a **Manage Security Control** button.
        * **Egress Security Score** card: Displays an aggregate egress security score, with a **Manage VPC/VNets** button.
        * **Total Threats** card: Displays **Logged** and **Denied** counts.
        * **Unique Threat IPs** card: Displays **Logged** and **Denied** counts.
        * **Geo-Traffic** card: Displays **Logged** and **Denied** counts.
        * **SaaS Services** panel: Per-service toggle buttons (for example, **Azure**, **GitHub**) showing traffic for the selected service.
        * **Intrusions** table: Displays intrusion counts by severity, with a **View All** button.

        ## Actions

        <AccordionGroup>
          <Accordion title="Filter the Dashboard">
            To filter the Dashboard based on time or VPC/VNet:

            1. In the **Filters panel**, select a **Time Period**, or set a custom **Start** and **End** date and time.
            2. Select a **VPC/VNet** and a traffic **Direction** to narrow the dashboard to a specific scope.

            The Dashboard updates to reflect the selected time period and scope.
          </Accordion>

          <Accordion title="Review the Threat Overview map">
            To review the geographic origin and destination of detected threats:

            1. Review the **Threat Overview** map for the geographic origin and destination of detected threats.
            2. Use the zoom in, zoom out, and reset view controls to adjust the map view.
          </Accordion>

          <Accordion title="Review the Security Control and Egress Security Score cards">
            To review coverage and egress security posture summaries:

            1. Review the **Monitored Rules** and **Protected Rules** counts on the **Security Control** card, or select **Manage Security Control** to go to the **Security Control** sub-tab.
            2. Review the **Egress Security Score** card for an aggregate score representing the security posture of egress traffic, or select **Manage VPC/VNets** to scope the score to specific VPCs or VNets.
          </Accordion>

          <Accordion title="Review the summary cards">
            To review threat and traffic summary counts:

            1. Review the **Logged** and **Denied** counts on the **Total Threats** and **Unique Threat IPs** cards for the selected time range.
            2. Review the **Logged** and **Denied** counts on the **Geo-Traffic** card. On the **SaaS Services** panel, select a service button (for example, **Azure** or **GitHub**) to view traffic for that service.
          </Accordion>

          <Accordion title="Review the Intrusions Table">
            To review intrusion counts by severity:

            1. Review the **Intrusions** table for a count of intrusions by severity.
            2. Select **View All** to open the full list of intrusion detection events.

            ### Parameter Details

            | Parameter     | Description                                              |
            | ------------- | -------------------------------------------------------- |
            | Critical      | The count of intrusions with **Critical** severity.      |
            | Major         | The count of intrusions with **Major** severity.         |
            | Minor         | The count of intrusions with **Minor** severity.         |
            | Informational | The count of intrusions with **Informational** severity. |
          </Accordion>

          <Accordion title="Review Identified Threats and Threats Activities">
            To review detected threats and their activity over time:

            1. Review the **Identified Threats** panel for a breakdown of threats by category and severity.
            2. Review the **Threats Activities** panel for a timeline of threat detections over the selected time range.
          </Accordion>
        </AccordionGroup>
      </Tab>

      <Tab title="Security Control">
        ## Purpose

        The **Security Control** sub-tab creates and manages security control templates that monitor or protect against specific categories of egress traffic and threat exposure.

        ## Elements

        <Frame>
          <img src="https://mintcdn.com/aviatrix-14b37c43/G_ugohXUfLjeuLC7/images/reference/ui/security/dcf-dashboard-security-control.png?fit=max&auto=format&n=G_ugohXUfLjeuLC7&q=85&s=70abce34dab79ddc03b6404418aa55e0" alt="Distributed Cloud Firewall Dashboard Security Control" width="100%" data-path="images/reference/ui/security/dcf-dashboard-security-control.png" />
        </Frame>

        * **Add Custom Security Control** button: Starts the workflow to create a custom security control.
        * **Explore Recommended Security Control** button: Opens the catalog of recommended security control templates.
        * **All Categories** filter: Filters the template catalog by category — **Threats**, **Geo-Traffic**, **SaaS Services**, **Workload Ports**, or **Web Categories**.
        * **Build Defense in Layers with Security Controls** panel: Onboarding guidance with an **Add Recommended Security Control** button.

        ## Actions

        <AccordionGroup>
          <Accordion title="Add a Recommended Security Control">
            To add a recommended security control:

            1. Select **Explore Recommended Security Control**, or use the **All Categories** filter to narrow the catalog to a specific category.
            2. Choose a control template from one of the available categories: **Threats**, **Geo-Traffic**, **SaaS Services**, **Workload Ports**, or **Web Categories**.
            3. Apply the template in **Monitor** mode to watch matching traffic and workloads before enforcing.
            4. Switch the control from **Monitor** to **Protect** to enforce active defense once the monitored data looks correct.

            ### Parameter Details

            | Category       | Description                                                                  |
            | -------------- | ---------------------------------------------------------------------------- |
            | Threats        | Monitors or protects against traffic matching known threat signatures.       |
            | Geo-Traffic    | Monitors or protects against traffic to or from specific geographic regions. |
            | SaaS Services  | Monitors or protects against traffic to or from specific SaaS applications.  |
            | Workload Ports | Monitors or protects against traffic on specific destination ports.          |
            | Web Categories | Monitors or protects against traffic to specific web content categories.     |
          </Accordion>

          <Accordion title="Add a Custom Security Control">
            To add a custom security control:

            1. Select **Add Custom Security Control**.
            2. Define the traffic match criteria and choose **Monitor** or **Protect** mode.
          </Accordion>

          <Accordion title="View a Security Control">
            To view a security control:

            1. Go to **Security** > **Distributed Cloud Firewall** > **Dashboard** > **Security Control**.<br />The list of configured security controls appears.
            2. Locate the security control and review its category, mode (**Monitor** or **Protect**), and monitored or protected rule counts.
            3. Optionally use the **All Categories** filter to narrow the list to a specific category.
          </Accordion>

          <Accordion title="Edit a Security Control">
            To edit a security control:

            1. Go to **Security** > **Distributed Cloud Firewall** > **Dashboard** > **Security Control**.<br />The list of configured security controls appears.
            2. Locate the security control and click **Edit** to update its match criteria or switch between **Monitor** and **Protect** mode.
            3. Click **Save**.

            A notification appears confirming the edit.
          </Accordion>

          <Accordion title="Delete a Security Control">
            To delete a security control:

            1. Go to **Security** > **Distributed Cloud Firewall** > **Dashboard** > **Security Control**.<br />The list of configured security controls appears.
            2. Locate the security control and click **Delete**.
            3. Read the warning message and confirm the deletion.

            A notification appears confirming the deletion.
          </Accordion>
        </AccordionGroup>
      </Tab>
    </Tabs>
  </Tab>

  <Tab title="Policies">
    ## Purpose

    The **Policies** page creates and manages distributed firewall policies for securing traffic across the multicloud environments.

    ## Elements

    <Frame>
      <img src={"/images/reference/ui/security/dcf-policies.png"} alt="Distributed Cloud Firewall: Policies" width="100%" />
    </Frame>

    * **+ Rule button**: Starts the workflow to create a new firewall rule.
    * **Manage Rulesets**: Opens the dialog to create, edit, or manage rulesets (groupings of rules). Create rulesets before adding rules to them (Controller 8.0 or later).
    * **Actions button**: Provides options to reset the hit count, change rule enforcement (Enforce, Monitor, or Disable), manage logging, and view rule distribution.
    * **Policy Table**: Displays the rule names and their details.
    * **Edit button**: Modifies an existing firewall rule in the table.
    * **Move button**: Changes the priority order of the firewall rules.
    * **Delete button**: Removes an existing firewall rule from the table.

    ## Actions

    <AccordionGroup>
      <Accordion title="View Ruleset">
        Each ruleset is a grouping of DCF rules with a priority that determines evaluation order.

        To view rulesets and the rules within a ruleset:

        1. Go to **Security** > **Distributed Cloud Firewall** > **Policies**.<br />The Policies page appears with the ruleset list and the Policy Table.
        2. To view the full list of rulesets and their order, click **Manage Rulesets**.<br />The **Manage Rulesets** dialog displays all rulesets and their priority order.
        3. Click **Close** to return to the Policies tab.
        4. On the Policies tab, select a ruleset from the ruleset list (dropdown or selector).<br />The Policy Table shows the rules in that ruleset.
        5. Optionally, use **Search** or **Filter** to find a rule within the ruleset.

        <Note>**Note:** Save changes for the current ruleset before switching to another.<br /><br />Requires Controller version 8.0 or later.</Note>
      </Accordion>

      <Accordion title="Manage Rulesets">
        Use **Manage Rulesets** on the Policies page to:

        * View all rulesets and their order
        * Create rulesets
        * Edit placement and names
        * Change ruleset priority
        * Reset traffic counts for selected rulesets
        * Commit draft changes

        <Note>**Note:** DCF rulesets require Controller version 8.0 or later.</Note>

        To manage rulesets:

        1. Go to **Security** > **Distributed Cloud Firewall** > **Policies**.
        2. Click **Manage Rulesets**.<br />The **Manage Rulesets** dialog appears.
        3. Click the edit icon to edit the ruleset and change the name and placement of the ruleset.
        4. Click the move icon to change the ruleset priority.
        5. Click the reset icon to reset the traffic counts for the selected rulesets.
        6. Click **Save**.
        7. Repeat steps 3–6 to create additional rulesets if needed.
        8. Click **Commit** to commit the saved changes.
        9. Click **Close**.
      </Accordion>

      <Accordion title="Create a DCF Ruleset">
        Create a ruleset before adding rules to it. You must use Controller version 8.0 or later to use DCF rulesets.

        To create a ruleset:

        1. Go to **Security** > **Distributed Cloud Firewall** > **Policies**.
        2. Click **Manage Rulesets**.<br />The **Manage Rulesets** dialog appears.
        3. Click **+ Ruleset**.<br />The **Create Ruleset** dialog appears.
        4. Configure **Name**, **Place Ruleset**, and **Existing Ruleset** (if applicable).<br />Refer to the Parameter Details table.
        5. Click **Save**.
        6. Repeat steps 3–5 to create additional rulesets if needed.
        7. Click **Close**.
        8. On the **Policies** tab, select a ruleset from the **Ruleset** dropdown to add rules to it.

        The new ruleset appears in the **Ruleset** dropdown. You can then add rules to the ruleset.

        ### Parameter Details

        | CoPilot Parameter Name | Description                                                                                                         |
        | ---------------------- | ------------------------------------------------------------------------------------------------------------------- |
        | Name                   | Enter a name for the ruleset.                                                                                       |
        | Place Ruleset          | Select where to place the ruleset: above or below an existing ruleset, or at the top or bottom of the ruleset list. |
        | Existing Ruleset       | If you select **Above** or **Below** in **Place Ruleset**, select the existing ruleset from this list.              |
      </Accordion>

      <Accordion title="Create Firewall Rule">
        To create a distributed firewall rule:

        1. Go to **Security** > **Distributed Cloud Firewall** > **Policies**.
        2. Click **+ Rule**.
        3. Configure the rule parameters. Refer to the Parameter Details table.
        4. Save the rule.

        The new rule appears in the Policy Table.

        ### Parameter Details

        | CoPilot Parameter Name | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
        | ---------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
        | Name                   | Distributed Cloud Firewall rule name.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
        | Source Groups          | The groups (SmartGroup, ExternalGroup, Threat Feed, Country) that originate traffic. You must create the SmartGroups and ExternalGroups before creating a DCF rule.<br /><br /><Note>**Note:** You must include at least one SmartGroup.<br /><br />You cannot have an ExternalGroup as both a source and a destination.</Note>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
        | Destination Groups     | The groups (SmartGroup, ExternalGroup, Threat Feed, Country) that terminate traffic. You must create the SmartGroups and ExternalGroups before creating a DCF rule.<br /><br /><Note>**Note:** You must include at least one SmartGroup.<br /><br />You cannot have an ExternalGroup as both a source and a destination.</Note><br /><br />If you are using Distributed Cloud Firewall rules for egress purposes, you must:<ul><li>Select **Public Internet** as the Destination SmartGroup.</li><li>Enable SNAT on the Spoke Gateways that enforce the egress policy.</li></ul><br />The Destination Group must be **Public Internet** if all of the following are true:<ul><li>You are creating a new rule.</li><li>The Destination Group has not already been modified.</li><li>At least one WebGroup has been selected.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
        | WebGroups              | Select the WebGroups that filter egress traffic. You must create these groups before creating a DCF rule.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
        | Protocol               | Select **TCP**, **UDP**, **ICMP**, or **Any**. If you select TCP or UDP you can enter a port number or port range.<br /><br /><Note>**Note:** If a WebGroup is included in the rule, a warning displays if any non-standard ports are selected for TCP or UDP. Non-standard ports are those that are not commonly used for the selected protocol, such as port 80 for HTTP or port 443 for HTTPS.<br /><br />The ICMP protocol is unavailable if a WebGroup is selected, because WebGroups are only supported for TLS traffic.<br /><br />If UDP or ICMP is selected, **Ensure TLS** and **TLS Decryption** toggles are unavailable.</Note>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
        | Port                   | Enter a port numbers or port range for the protocol.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
        | Enforcement            | Controls how the rule participates in policy evaluation. Available in Controller 10.1.0 or later. In Controller 10.1.0, this field changes from a two-value slider to a three-value dropdown, adding a new **Disable** option.<br /><br /><ul><li>**Enforce** (default): The rule is active and its action is applied to matching traffic. Hit counters increment and logs are produced according to the **Log** setting.</li><li>**Monitor**: The rule is evaluated for match purposes but the action is not applied — matching traffic is permitted. Use this to observe which traffic would match a rule before you enforce it.</li><li>**Disable**: The rule is skipped entirely. No traffic is matched, no hit counters increment, and no logs are produced. The rule remains in the Policy Table so you can re-enable it later without recreating it.</li></ul>After the rule is created, you can change its enforcement setting from the row-level **Actions** menu next to the rule.<br /><br /><Note>**Note:** The **Disable** option is not available for rules created through a Kubernetes Custom Resource Definition (CRD) in Controller 10.1.0. CRD-managed rules recognize only **Enforce** and **Monitor**. CRD support for the **Disable** option is planned for Controller 10.2.0.</Note> |
        | Log                    | <ul><li>**At Start**: Logs when the session starts, only the initial connection metadata is logged.</li><li>**At Start & End**: Logs both metadata and session statistics (session end time, packets received/transmitted, bytes received/transmitted, and so on).</li><li>**At End**: Log when the session ends, a single log is created that contains full session statistics (session end time, packets received/transmitted, bytes received/transmitted, and so on).</li><li>**Off**: Disables logging.</li></ul><Note>**Note:** Aviatrix recommends not logging Permit rules.</Note>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
        | **Rule Behavior**      |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
        | Action                 | Select **Permit** or **Deny**. This determines the action applied to matching traffic.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
        | SG Orchestration       | **On**: The rule is available for Security Group Orchestration.<br /><br />The SG Orchestration toggle is **Off** for new rules when any of the following are true:<ul><li>A WebGroup is present in the rule.</li><li>Source Group is **Anywhere** and action is **Permit**.</li><li>Source Group is **Anywhere**, Destination Group is **Anywhere**, and action is **Deny**.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
        | Ensure TLS             | Turn **On** if you want traffic that matches the ports and Source and Destination Groups but that is not TLS to be denied. Traffic is denied (dropped) even if HTTP traffic matches domains or URLs in WebGroups.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
        | TLS Decryption         | Turn On to enable TLS decryption.<br /><br /><Danger>**Important:** TLS Decryption must be enabled if a URL-based WebGroup is selected.</Danger><br /><br />TLS decryption intercepts encrypted HTTPS traffic, decrypts it for inspection, then re-encrypts it toward the destination.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
        | Intrusion Analysis     | When Intrusion Detection is enabled, traffic is inspected for threats and results appear on **Detected Intrusions**. When Intrusion Detection and TLS Decryption are both enabled, the TLS stream is temporarily decrypted and inspected for intrusions.<br /><br /><Note>**Note:** Download the Aviatrix CA certificate (Controller 7.0) or upload your own certificate (Controller 7.1 or later) before creating a policy that uses IDS or TLS Decryption.</Note>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
        | TLS Profile            | Select the TLS profile to use for the rule.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
        | **Rule Priority**      |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
        | Place Rule             | Select **Above**, **Below**, **Top**, **Bottom**, or **Priority**.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
        | Existing Rule          | If you select **Above** or **Below** for Place Rule, select the existing rule whose position is affected by the new rule.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
        | Priority Number        | If you selected **Priority** for Place Rule, enter a priority number for the new rule. If another rule already has that priority, it moves down in the list. Zero (**0**) is the highest priority number. You can change rule priority after creation using the arrow icon next to the rule in the Rule table.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
      </Accordion>

      <Accordion title="Edit Firewall Rule">
        To edit an existing firewall rule:

        1. Go to **Security** > **Distributed Cloud Firewall** > **Policies**.
        2. Locate the rule in the Policy table and click the **Edit** button.
        3. Update the desired parameters.
        4. Save your changes.

        Changes take effect after saving.
      </Accordion>

      <Accordion title="Move Firewall Rule">
        To change the priority order of firewall rules:

        1. Go to **Security** > **Distributed Cloud Firewall** > **Policies**.
        2. Locate the rule in the Policy Table and click the **Move** button.
        3. Move the rule to the desired position in the priority order.
        4. Save the new order.

        Rule priority determines the order in which rules are evaluated.
      </Accordion>

      <Accordion title="Delete Firewall Rule">
        To delete a firewall rule:

        1. Go to **Security** > **Distributed Cloud Firewall** > **Policies**.
        2. Locate the rule in the Policy Table and click the **Delete** button.
        3. Confirm the deletion.

        The rule is removed from the Policy Table.
      </Accordion>

      <Accordion title="Change Rule Enforcement, Reset Hit Count, or Manage Logging">
        To change a rule's enforcement, reset its hit count, or manage logging:

        1. Go to **Security** > **Distributed Cloud Firewall** > **Policies**.
        2. Locate the rule in the Policy Table and open the row-level **Actions** menu.
        3. Select the action you want to apply — for example, **Reset Hit Count**, or change the rule's enforcement to **Enforce**, **Monitor**, or **Disable**, or change logging.

        The selected action is applied to the rule.

        <Note>**Note:** The **Disable** option is new in Controller 10.1.0. A rule set to **Disable** is skipped entirely by policy evaluation, so it does not match traffic, increment hit counters, or produce logs. This differs from **Monitor**, which keeps the rule in evaluation but suppresses its action (matching traffic is permitted, and logs are still produced according to the **Log** setting).<br /><br />Rules created through a Kubernetes Custom Resource Definition (CRD) cannot use the **Disable** option in Controller 10.1.0. CRD-managed rules recognize only **Enforce** and **Monitor**.</Note>
      </Accordion>
    </AccordionGroup>
  </Tab>

  <Tab title="Monitor">
    <Tabs>
      <Tab title="Policy Logs">
        ### Purpose

        The **Policy Logs** page displays traffic logs generated by the Distributed Cloud Firewall policies. It helps monitor allowed and denied traffic, and supports troubleshooting and audit of policy enforcement across cloud networks.

        ### Elements

        <Frame>
          <img src={"/images/reference/ui/security/dcf-policy-logs.png"} alt="Distributed Cloud Firewall: Policy Logs" width="100%" />
        </Frame>

        * **Auto Refresh toggle**: Enables or disables automatic refreshing of the log data.
        * **Policy Logs table**: Displays policy rule logs and their details.

        ### Actions

        <AccordionGroup>
          <Accordion title="View Policy Logs">
            To view Distributed Cloud Firewall policy logs:

            1. Go to **Security** > **Distributed Cloud Firewall** > **Monitor**.<br />Select the **Policy Logs** tab.
            2. The Policy Logs page appears with the Policy Logs table.
            3. Review traffic logs for allowed and denied traffic.
            4. Optionally, use the **Auto Refresh** toggle to enable or disable automatic refreshing of log data.

            The table displays policy rule logs with timestamp, rule, gateway, source and destination IPs, and other traffic details for troubleshooting and audit.

            <Note>
              **<a href={"/docs/enterprise/" + "10.1" + "/reference/feature-modes/index#preview-features"}>Preview</a> feature.** The **Log Enrichment Fields** listed below appear in the Policy Logs table only after you turn on **Log Enrichment**, which is turned off by default. Go to **Security** > **Distributed Cloud Firewall** > **Settings** to turn it on. Requires CoPilot 4.37 or later.
            </Note>

            ### Parameter Details

            | CoPilot Parameter Name              | Description                                                                                                                                                                                                                                                                                          |
            | ----------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
            | Timestamp                           | Shows the date and time when the traffic log is recorded.                                                                                                                                                                                                                                            |
            | Rule                                | Shows the firewall policy rule that matches the traffic.                                                                                                                                                                                                                                             |
            | Gateway                             | Shows the gateway that processes the traffic.                                                                                                                                                                                                                                                        |
            | Source IP                           | Shows the source IP address of the traffic.                                                                                                                                                                                                                                                          |
            | Destination IP                      | Shows the destination IP address of the traffic.                                                                                                                                                                                                                                                     |
            | Source MAC address                  | Shows the source MAC address of the traffic.                                                                                                                                                                                                                                                         |
            | Destination MAC address             | Shows the destination MAC address of the traffic.                                                                                                                                                                                                                                                    |
            | SNI                                 | Shows the server name indication extracted from TLS traffic.                                                                                                                                                                                                                                         |
            | Decrypted by                        | Shows the gateway that performs traffic decryption.                                                                                                                                                                                                                                                  |
            | URL                                 | Shows the destination URL accessed by the traffic.                                                                                                                                                                                                                                                   |
            | Protocol                            | Shows the traffic protocol such as TCP, UDP, or ICMP.                                                                                                                                                                                                                                                |
            | Source port                         | Shows the source port number used by the traffic.                                                                                                                                                                                                                                                    |
            | Destination port                    | Shows the destination port number used by the traffic.                                                                                                                                                                                                                                               |
            | Reason                              | Shows the reason for the policy decision.                                                                                                                                                                                                                                                            |
            | Action                              | Shows whether the traffic is allowed or denied.                                                                                                                                                                                                                                                      |
            | Enforced                            | Shows whether the policy enforcement is applied.                                                                                                                                                                                                                                                     |
            | **Log Enrichment Fields (Preview)** |                                                                                                                                                                                                                                                                                                      |
            | Tags                                | Shows the cloud resource tags for the resource associated with the traffic, as key-value pairs from your cloud account.                                                                                                                                                                              |
            | EU Region                           | Shows whether the resource associated with the traffic is located in the European Union.                                                                                                                                                                                                             |
            | Service Name                        | Shows the name of the cloud service that matches an ExternalGroup in the rule, such as a storage or database service.                                                                                                                                                                                |
            | Threat Severity                     | Shows the severity of the matched entry when the rule includes a Threat Feed group.<ul><li>**Critical**: The highest severity level.</li><li>**Major**: A high severity level.</li><li>**Minor**: A low severity level.</li><li>**Informational**: No severity; provided for context only.</li></ul> |
            | Threat Type                         | Shows the threat category from the threat intelligence feed when the rule includes a Threat Feed group. Available categories depend on the feed and can change as the feed updates.                                                                                                                  |
          </Accordion>
        </AccordionGroup>
      </Tab>

      <Tab title="Intrusion Logs">
        ### Purpose

        The **Intrusion Logs** page displays security events detected by the Distributed Cloud Firewall intrusion detection engine. It helps identify suspicious traffic, analyze threats, and support security investigation across cloud environments.

        ### Elements

        <Frame>
          <img src={"/images/reference/ui/security/dcf-intrusion-logs.png"} alt="Distributed Cloud Firewall: Intrusion Logs" width="100%" />
        </Frame>

        * **Intrusion Logs table**: Displays intrusion detection logs and their details.

        ### Actions

        <AccordionGroup>
          <Accordion title="View Intrusion Logs">
            To view Distributed Cloud Firewall intrusion detection logs:

            1. Go to **Security** > **Distributed Cloud Firewall** > **Monitor**.<br />Select the **Intrusion Logs** tab.
            2. The Intrusion Logs page appears with the Intrusion Logs table.
            3. Review security events detected by the intrusion detection engine.

            The table displays intrusion logs with timestamp, severity, source and destination IPs, protocol, and attack details for security investigation.

            ### Parameter Details

            | CoPilot Parameter Name | Description                                                   |
            | ---------------------- | ------------------------------------------------------------- |
            | Timestamp              | Shows the date and time when the intrusion event is recorded. |
            | Severity               | Shows the severity level of the detected intrusion.           |
            | Source IP              | Shows the source IP address of the traffic.                   |
            | Destination IP         | Shows the destination IP address of the traffic.              |
            | Protocol               | Shows the network protocol used by the traffic.               |
            | Source port            | Shows the source port number used by the traffic.             |
            | Destination port       | Shows the destination port number used by the traffic.        |
            | Application protocol   | Shows the application-level protocol detected in the traffic. |
            | Gateway                | Shows the gateway where the intrusion is detected.            |
            | Category               | Shows the intrusion category or attack type.                  |
            | Attack target          | Shows the target resource of the detected attack.             |
            | Deployment             | Shows the deployment or environment where the event occurs.   |
          </Accordion>
        </AccordionGroup>
      </Tab>
    </Tabs>
  </Tab>

  <Tab title="Audit">
    ## Purpose

    The **Audit** page displays audit logs for Distributed Cloud Firewall operations. It helps track user actions, review configuration changes, and support security audit and troubleshooting activities.

    ## Elements

    <Frame>
      <img src={"/images/reference/ui/security/dcf-audit.png"} alt="Distributed Cloud Firewall: Audit" width="100%" />
    </Frame>

    * **Time Period filter**: Filters audit logs based on a selected time range.

    ## Actions

    <AccordionGroup>
      <Accordion title="View Audit Logs">
        To view Distributed Cloud Firewall audit logs:

        1. Go to **Security** > **Distributed Cloud Firewall** > **Audit**.
        2. The Audit page appears with audit logs for DCF operations.
        3. Optionally, use the **Time Period** filter to filter logs by a selected time range.
        4. Review user actions, configuration changes, and audit findings.

        The audit logs help track user actions and support security audit and troubleshooting activities.

        ### Parameter Details

        | CoPilot Parameter Name | Description                                              |
        | ---------------------- | -------------------------------------------------------- |
        | Check Name             | Shows the name of the audit check performed.             |
        | Status                 | Shows whether the audit check passed or failed.          |
        | Severity               | Shows the severity level of the audit finding.           |
        | Resource               | Shows the resource associated with the audit finding.    |
        | Details                | Provides additional information about the audit finding. |
      </Accordion>
    </AccordionGroup>
  </Tab>

  <Tab title="IPS">
    <Tabs>
      <Tab title="Applied VPC/VNets">
        ## Purpose

        The **Applied VPC/VNets** page summarizes where intrusion prevention is applied across VPCs and VNets and helps you confirm IPS coverage before you change profiles or rule feeds.

        ## Elements

        <Frame>
          <img src={"/images/reference/ui/security/dcf-ips-applied-vpc-vnets.png"} alt="Distributed Cloud Firewall: IPS Applied VPC/VNets" width="100%" />
        </Frame>

        * **+ VPC/VNet button**: Opens a form to add IPS profile to a VPC/VNet.
        * **Search bar**: Narrow the applied VPC/VNets table by name or attributes.
        * **Applied VPC/VNets table**: Lists the VPCs and VNets where IPS is applied.
        * **Edit button**: Opens a form to change the IPS profile applied to the VPC/VNet.
        * **Remove button**: Removes the IPS profile from the VPC/VNet.

        ## Actions

        <AccordionGroup>
          <Accordion title="View Applied VPC/VNets">
            To view the VPC/VNets where IPS is applied:

            1. Go to **Security** > **Distributed Cloud Firewall** > **IPS** > **Applied VPC/VNets**.
            2. The Applied VPC/VNets page appears with the Applied VPC/VNets table.<br />Refer to the Parameter Details table for the details of the Applied VPC/VNets parameters.
            3. Optionally use **Search** or the table toolbar filters to narrow rows.

            The table displays the VPCs and VNets where IPS is applied.

            ### Parameter Details

            | CoPilot Parameter Name | Description                                                                |
            | ---------------------- | -------------------------------------------------------------------------- |
            | Name                   | The name of the VPC/VNet.                                                  |
            | Profile                | The name of the IPS profile applied to the VPC/VNet.                       |
            | Gateway                | The name of the Gateways in the VPC/VNet where the IPS profile is applied. |
            | IP CIDRs               | The IP CIDRs of the VPC/VNet.                                              |
            | Cloud                  | The Cloud provider of the VPC/VNet.                                        |
            | Region                 | The region of the VPC/VNet.                                                |
          </Accordion>

          <Accordion title="Add an IPS Profile to a VPC/VNet">
            To add an IPS profile to a VPC/VNet:

            1. Go to **Security** > **Distributed Cloud Firewall** > **IPS** > **Applied VPC/VNets**.
            2. Click **+ VPC/VNet**.
            3. Select the VPC/VNet from the dropdown.
            4. Select the IPS profile from the dropdown.
            5. Click **Save**.
               A notification appears confirming the addition of the IPS profile to the VPC/VNet.
          </Accordion>

          <Accordion title="Edit an IPS Profile on a VPC/VNet">
            To edit an IPS profile on a VPC/VNet:

            1. Go to **Security** > **Distributed Cloud Firewall** > **IPS** > **Applied VPC/VNets**.
            2. Locate the VPC/VNet in the table and click the edit icon.<br />The Edit IPS Profile form appears.
            3. Select the new IPS profile from the dropdown.
            4. Click **Save**.
               A notification appears confirming the edit of the IPS profile on the VPC/VNet.
          </Accordion>

          <Accordion title="Remove an IPS Profile from a VPC/VNet">
            To remove an IPS profile from a VPC/VNet:

            1. Go to **Security** > **Distributed Cloud Firewall** > **IPS** > **Applied VPC/VNets**.
            2. Locate the VPC/VNet in the table and click the remove icon.<br />The Remove IPS Profile confirmation dialog appears.
            3. Read and understand the message, and tick to confirm the removal.
            4. Click **Remove**.
               A notification appears confirming the removal of the IPS profile from the VPC/VNet.
          </Accordion>
        </AccordionGroup>
      </Tab>

      <Tab title="Profiles">
        ## Purpose

        The **Profiles** page lists intrusion prevention profiles that you can attach to DCF rules for the prevention of network intrusions.

        ## Elements

        <Frame>
          <img src={"/images/reference/ui/security/dcf-ips-profiles.png"} alt="Distributed Cloud Firewall: IPS Profiles" width="100%" />
        </Frame>

        * **+ Custom Profile**: Opens the flow to define a new custom IPS profile.
        * **Profiles table**: Lists added custom IPS profiles.
        * **Search bar**: Narrow the profiles table by name or attributes.
        * **Edit**: Edits a custom IPS profile.
        * **Delete**: Deletes a custom IPS profile.
        * **Actions**: Opens the context menu to clone a profile and set an IPS profile active.

        ## Actions

        <AccordionGroup>
          <Accordion title="View IPS Profiles">
            To view the IPS Profiles:

            1. Go to **Security** > **Distributed Cloud Firewall** > **IPS** > **Profiles**.
            2. The IPS Profiles page appears with the IPS Profiles table.
            3. Refer to the Parameter Details table for the details of the IPS profiles parameters.
            4. Optionally use **Search** or the table toolbar filters to narrow rows.

            The table displays the built-in and custom IPS profiles.

            ### Parameter Details

            | CoPilot Parameter Name | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
            | ---------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
            | Name                   | The name of the IPS profile.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
            | Drop Level             | The minimum Suricata signature severity level at which matching traffic is dropped.<ul><li>**Only Critical Severity**: Drops traffic that matches a signature with Critical severity only.</li><li>**Major and Higher Severity**: Drops traffic that matches a signature with Major or Critical severity.</li> <li>**Minor and Higher Severity**: Drops traffic that matches a signature with Minor, Major, or Critical severity.</li><li>**All Severities**: Drops traffic that matches any signature regardless of severity level. </li><li>**No Drops**: No traffic is dropped. All matching signatures generate an alert only. </li></ul> |
            | Log Level              | The severity level at which alerts are generated.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
            | SID Exceptions         | The total number of Signature ID (SID) overrides configured on the profile. Includes both Ignored SIDs (fully suppressed — no alert or drop) and Alert Only SIDs (alert generated, traffic not dropped)                                                                                                                                                                                                                                                                                                                                                                                                                                       |
          </Accordion>

          <Accordion title="View an IPS Profile">
            To view an IPS Profile:

            1. Go to **Security** > **Distributed Cloud Firewall** > **IPS** > **Profiles**.
            2. Locate the IPS Profile in the table and click the profile name.
            3. The IPS Profile details page appears with the IPS Profile details.
            4. Refer to the Parameter Details table for the details of the IPS Profile parameters.

            ### Parameter Details

            | CoPilot Parameter Name | Description                                 |
            | ---------------------- | ------------------------------------------- |
            | *Name*                 | The name of the IPS profile.                |
            | Drop Level             |                                             |
            | Log Level              |                                             |
            | Rule Feeds             |                                             |
            | SID                    | The SID exceptions in the IPS profile.      |
            | Action                 | The action to take when the SID is matched. |
          </Accordion>

          <Accordion title="Create a Custom IPS profile">
            To create a custom IPS profile:

            1. Go to **Security** > **Distributed Cloud Firewall** > **IPS** > **Profiles**.
            2. Click **+ Custom Profile**.
            3. Configure the profile parameters. Refer to the Parameter Details table.
            4. Click **Save**.

            A notification appears confirming the creation of the custom IPS profile.

            ### Parameter Details

            | CoPilot Parameter Name | Description                                                                                                                                                                     |
            | ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
            | Name                   | The name of the IPS profile.                                                                                                                                                    |
            | Rule Feed              |                                                                                                                                                                                 |
            | Drop Level             | <ul><li>**Only Critical Severity**: </li><li>**Major and Higher Severity**:</li> <li>**Minor and Higher Severity**:</li><li>**All Severities**:</li><li>**No Drops**:</li></ul> |
            | Alert Level            |                                                                                                                                                                                 |
          </Accordion>

          <Accordion title="Edit an IPS profile">
            To change an existing profile:

            1. Go to **Security** > **Distributed Cloud Firewall** > **IPS** > **Profiles**.
            2. Locate the IPS Profile in the table and click the edit icon.<br />The Edit IPS Profile form appears.
            3. Update the profile parameters. Refer to the Parameter Details table.
            4. Click **Save**.

            A notification appears confirming the edit of the IPS Profile.

            ### Parameter Details

            | CoPilot Parameter Name | Description                                                                                                                                                                     |
            | ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
            | Name                   | The name of the IPS profile.                                                                                                                                                    |
            | Rule Feed              |                                                                                                                                                                                 |
            | Drop Level             | <ul><li>**Only Critical Severity**: </li><li>**Major and Higher Severity**:</li> <li>**Minor and Higher Severity**:</li><li>**All Severities**:</li><li>**No Drops**:</li></ul> |
            | Alert Level            |                                                                                                                                                                                 |
          </Accordion>

          <Accordion title="Delete an IPS profile">
            To delete an IPS Profile:

            1. Go to **Security** > **Distributed Cloud Firewall** > **IPS** > **Profiles**.
            2. Locate the IPS Profile in the table and click the delete icon.<br />The Delete IPS Profile confirmation dialog appears.
            3. Click **Delete**.

            The IPS Profile table updates with the new list of IPS profiles.
          </Accordion>

          <Accordion title="Clone an IPS Profile">
            To clone an IPS Profile:

            1. Go to **Security** > **Distributed Cloud Firewall** > **IPS** > **Profiles**.
            2. Locate the IPS Profile in the table and click Actions (⋮) > **Clone profile**.<br />The Clone Profile form appears.
            3. Update the profile parameters. Refer to the Parameter Details table.
            4. Click **Clone**.

            A notification appears confirming the cloning of the IPS Profile.

            ### Parameter Details

            | CoPilot Parameter Name | Description                                                                                                                                                                     |
            | ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
            | Name                   | The name of the IPS profile.                                                                                                                                                    |
            | Rule Feed              |                                                                                                                                                                                 |
            | Drop Level             | <ul><li>**Only Critical Severity**: </li><li>**Major and Higher Severity**:</li> <li>**Minor and Higher Severity**:</li><li>**All Severities**:</li><li>**No Drops**:</li></ul> |
            | Alert Level            |                                                                                                                                                                                 |
          </Accordion>

          <Accordion title="Set an IPS Profile Active">
            To set an IPS Profile active:

            1. Go to **Security** > **Distributed Cloud Firewall** > **IPS** > **Profiles**.
            2. Locate the IPS Profile in the table and click Actions (⋮) > **Set As Active**.
            3. Read and understand the message, and tick to confirm the setting.
            4. Click **Apply**.

            A notification appears confirming the setting of the IPS Profile active.
          </Accordion>
        </AccordionGroup>
      </Tab>

      <Tab title="Rules Feeds">
        ## Purpose

        The **Rules Feeds** page lists intrusion prevention rules used when IPS inspection runs for Distributed Cloud Firewall.

        ## Elements

        <Frame>
          <img src={"/images/reference/ui/security/dcf-ips-rules.png"} alt="Distributed Cloud Firewall: IPS Rules" width="100%" />
        </Frame>

        * **+ Custom Rule Feed**: Opens the form to define a new custom IPS rule.
        * **Rules table**: Lists added custom IPS rules.
        * **Search bar**: Narrow the rules table by name or attributes.
        * **Edit button**: Edits a custom IPS rule.
        * **Delete button**: Deletes a custom IPS rule.
        * **Actions (⋮) button**: Opens the context menu to download a rule feed.

        ## Actions

        <AccordionGroup>
          <Accordion title="View Custom Rules">
            To view the Custom Rules:

            1. Go to **Security** > **Distributed Cloud Firewall** > **IPS** > **Rules Feeds**.
            2. The Custom Rules page appears with the Custom Rules table.
            3. Refer to the Parameter Details table for the details of the Custom Rules parameters.
            4. Optionally use **Search** or the table toolbar filters to narrow rows.

            The table displays the added custom rules.

            ### Parameter Details

            | CoPilot Parameter Name | Description                                             |
            | ---------------------- | ------------------------------------------------------- |
            | Name                   | The name of the custom IPS rule.                        |
            | Rules                  | The number of rules in the custom IPS rule.             |
            | Last Updated           | The date and time the custom IPS rule was last updated. |
          </Accordion>

          <Accordion title="View a Custom Rule">
            To view a custom Rule:

            1. Go to **Security** > **Distributed Cloud Firewall** > **IPS** > **Rules Feeds**.
            2. Locate the custom Rule in the table and click the name of the rule.<br />The Custom Rule details page appears with the Custom Rule details.<br />Refer to the Parameter Details table for the details of the Custom Rule parameters.

            The Custom Rule details page displays the Custom Rule, the rule syntax.

            ### Parameter Details

            | CoPilot Parameter Name | Description                      |
            | ---------------------- | -------------------------------- |
            | SID                    | The SID of the custom Rule.      |
            | Content                | The content of the custom Rule.  |
            | Severity               | The severity of the custom Rule. |
          </Accordion>

          <Accordion title="Create a Custom Rule Feed">
            To create a custom Rule Feed:

            1. Go to **Security** > **Distributed Cloud Firewall** > **IPS** > **Rules Feeds**.
            2. Click **+ Custom Rule Feed**.
            3. Enter the name of the custom IPS rule.
            4. Upload the custom IPS rule feed file.
            5. Click **Upload**.

            A notification appears confirming the creation of the custom Rule Feed.
          </Accordion>

          <Accordion title="Edit a Custom Rule Feed">
            To edit a custom Rule Feed:

            1. Go to **Security** > **Distributed Cloud Firewall** > **IPS** > **Rules Feeds**.
            2. Locate the custom Rule Feed in the table and click the edit icon in the row.<br />The Edit Custom Rule Feed form appears.
            3. Update the name of the custom Rule Feed and upload new rule feed file.
            4. Click **Upload**.

            A notification appears confirming the update of the custom Rule Feed.
          </Accordion>

          <Accordion title="Edit a Custom Rule Syntax">
            To edit a custom Rule Syntax:

            1. Go to **Security** > **Distributed Cloud Firewall** > **IPS** > **Rules Feeds**.
            2. Locate the custom Rule Feed in the table and click the name of the rule.<br />The Custom Rule Syntax details page appears with a table of the SID and the rule syntax.
            3. Click the edit icon in the row and edit the rule syntax.
            4. Turn On the **Suricata Rule Syntax** toggle to edit the rule syntax in the Suricata format.<br />Refer to the Parameter Details table for the details of the Suricata Rule Syntax parameters.
            5. Click **Save**.
               A notification appears confirming the update of the custom Rule Syntax.

            ### Parameter Details

            | CoPilot Parameter Name | Description                                                                                                                                                                     |
            | ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
            | Severity               | <ul><li>**Informational**: </li><li>**Minor**: </li><li>**Major**: </li><li>**Critical**: </li><li>**Unknown**: </li></ul>                                                      |
            | **Rule**               |                                                                                                                                                                                 |
            | Action                 | <ul><li>**Alert**: </li><li>**Pass**: </li><li>**Drop**: </li><li>**Reject**: </li><li>**Reject Source**: </li><li>**Reject Destination**: </li><li>**Reject Both**: </li></ul> |
            | Protocol               | <ul><li>ip: </li><li>tcp: </li></ul>                                                                                                                                            |
            | Direction              | <ul><li>Unidirectional: </li><li>Bidirectional: </li><li>Stateful:</li></ul>                                                                                                    |
            | Source                 |                                                                                                                                                                                 |
            | Source Port            |                                                                                                                                                                                 |
            | Destination            |                                                                                                                                                                                 |
            | Destination Port       |                                                                                                                                                                                 |
            | Options                |                                                                                                                                                                                 |
          </Accordion>

          <Accordion title="Delete a Custom Rule Feed">
            To delete a custom Rule Feed:

            1. Go to **Security** > **Distributed Cloud Firewall** > **IPS** > **Rules Feeds**.
            2. Locate the custom Rule Feed in the table and click the delete icon in the row.<br />The Delete Custom Rule Feed confirmation dialog appears.
            3. Click **Delete**.
               A notification appears confirming the deletion of the custom Rule Feed.
          </Accordion>

          <Accordion title="Download a Custom Rule Feed">
            To download a custom Rule Feed:

            1. Go to **Security** > **Distributed Cloud Firewall** > **IPS** > **Rules Feeds**.
            2. Locate the custom Rule Feed in the table and click the Actions icon (⋮) in the row.<br />The Actions menu appears.
            3. Click **Download Rule Feed**.
               A notification appears on your browser confirming the download of the custom Rule Feed.
          </Accordion>
        </AccordionGroup>
      </Tab>
    </Tabs>
  </Tab>

  <Tab title="TLS">
    <Tabs>
      <Tab title="Profiles">
        ### Purpose

        The **Profiles** page is a central management hub for creating, configuring, and managing TLS Profile objects that control how the Distributed Cloud Firewall inspects, validates, and decrypts TLS traffic.

        ### Elements

        <Frame>
          <img src={"/images/reference/ui/security/dcf-tls-profiles.png"} alt="Distributed Cloud Firewall: TLS Profiles" width="100%" />
        </Frame>

        * **+ Custom Profile**: Opens the flow to create a new custom TLS profile.
        * **Search**: Filters rows in the profiles table.
        * **Profiles table**: Shows the list of TLS profiles and their trust and enforcement settings.
        * Actions: Edit, Delete, and More (⋮) buttons to edit, delete, and clone a profile.

        ### Actions

        <AccordionGroup>
          <Accordion title="View TLS Profiles">
            To view TLS profiles and their trust and enforcement settings:

            1. Go to **Security** > **Distributed Cloud Firewall** > **TLS** > **Profiles**.<br />The Profiles page appears with the Profiles table.
            2. Refer to the Parameter Details table for the details of the TLS profiles parameters.
            3. Optionally use **Search** or the table toolbar filters to narrow rows.
               The table displays TLS profiles with their name, trust bundle, SNI verification, and enforcement settings.

            ### Parameter Details

            | CoPilot Parameter Name | Description                                                                                                                                                                                                                                                 |
            | ---------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
            | Name                   | The name of the TLS profile.                                                                                                                                                                                                                                |
            | Trust Bundle           | Collection of CA certificates used to validate the origin server's certificate when this TLS profile is applied to a rule.                                                                                                                                  |
            | SNI Verification       | <ul><li>**On**: Server Name Indication verification is enforced for decrypted sessions using this profile.</li><li>**Off**: Server Name Indication verification is not enforced for decrypted sessions using this profile.</li></ul>                        |
            | Enforcement            | <ul><li>**Permissive**: Checks are performed; failures are logged but traffic is allowed.</li><li>**Strict**: Checks are performed; failures cause the connection to be terminated.</li><li>**None**: No certificate or SNI checks are performed.</li></ul> |

            The **Default SNI Verify** row is a built-in default profile (marked **Default**) and cannot be deleted.
          </Accordion>

          <Accordion title="Create a TLS Profile">
            To create a custom TLS profile:

            1. Go to **Security** > **Distributed Cloud Firewall** > **TLS** > **Profiles**.
            2. Click **+ Custom Profile**.
            3. Configure the profile parameters. Refer to the Parameter Details table.
            4. Click **Save**.

            ### Parameter Details

            | CoPilot Parameter Name | Description                                                                                                                                                                                                                                                 |
            | ---------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
            | Name                   | Enter a name for the TLS profile.                                                                                                                                                                                                                           |
            | Trust Bundle           | Collection of CA certificates used to validate the origin server's certificate when this TLS profile is applied to a rule.                                                                                                                                  |
            | SNI Verification       | <ul><li>**On**: Server Name Indication verification is enforced for decrypted sessions using this profile.</li><li>**Off**: Server Name Indication verification is not enforced for decrypted sessions using this profile.</li></ul>                        |
            | Enforcement            | <ul><li>**Permissive**: Checks are performed; failures are logged but traffic is allowed.</li><li>**Strict**: Checks are performed; failures cause the connection to be terminated.</li><li>**None**: No certificate or SNI checks are performed.</li></ul> |

            The new profile appears in the table and can be selected where TLS profiles are referenced (for example, from DCF policy rules that support TLS profile selection).
          </Accordion>

          <Accordion title="Edit a TLS Profile">
            To edit a TLS profile:

            1. Go to **Security** > **Distributed Cloud Firewall** > **TLS** > **Profiles**.<br />The Profiles page appears with the Profiles table.
            2. Locate the profile and use **Edit** to update the profile parameters. Refer to the Parameter Details table.
            3. Use **More actions** (⋮) and click **Clone** to create a copy of the profile.
            4. Click **Save**.

            A notification appears confirming the edit.

            ### Parameter Details

            | CoPilot Parameter Name | Description                                                                                                                                                                                                                                                 |
            | ---------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
            | Name                   | The name of the TLS profile.                                                                                                                                                                                                                                |
            | Trust Bundle           | Collection of CA certificates used to validate the origin server's certificate when this TLS profile is applied to a rule.                                                                                                                                  |
            | SNI Verification       | <ul><li>**On**: Server Name Indication verification is enforced for decrypted sessions using this profile.</li><li>**Off**: Server Name Indication verification is not enforced for decrypted sessions using this profile.</li></ul>                        |
            | Enforcement            | <ul><li>**Permissive**: Checks are performed; failures are logged but traffic is allowed.</li><li>**Strict**: Checks are performed; failures cause the connection to be terminated.</li><li>**None**: No certificate or SNI checks are performed.</li></ul> |
          </Accordion>

          <Accordion title="Delete a TLS Profile">
            To delete a TLS profile:

            1. Go to **Security** > **Distributed Cloud Firewall** > **TLS** > **Profiles**.<br />The Profiles page appears with the Profiles table.
            2. Locate the profile and click **Delete**.
            3. Read the warning message and tick to confirm the deletion.
            4. Click **Delete**.
               A notification appears confirming the deletion.
          </Accordion>
        </AccordionGroup>
      </Tab>

      <Tab title="Decryption CA Certificates">
        ### Purpose

        The **Decryption CA Certificates** page shows the CoPilot-managed **Decryption CA** used for TLS decryption in DCF flows, its validity, association to a trust bundle, and actions to renew or download the certificate.

        ### Elements

        <Frame>
          <img src={"/images/reference/ui/security/dcf-tls-decryption-ca.png"} alt="Distributed Cloud Firewall: Decryption CA Certificate" width="100%" />
        </Frame>

        * **Decryption CA Certificate** Certificate card showing the certificate details such as name, expiry date, and trust bundle association.
        * **Renew Certificate** button: Button to renew the decryption CA certificate.
        * **Download Certificate** button: Button to download the decryption CA certificate.
        * **More Options dropdown**: The dropdown menu contains the following options:
          * **Upload New Certificate**: Button to upload a new certificate.
          * **Upload New Trust Bundle**: Button to upload a new trust bundle.
          * **Remove Certificate**: Button to remove the certificate.
          * **Remove Trust Bundle**: Button to remove the trust bundle.

        ### Actions

        <AccordionGroup>
          <Accordion title="Renew a Decryption CA Certificate">
            To renew a Decryption CA certificate:

            1. Go to **Security** > **Distributed Cloud Firewall** > **TLS** > **Decryption CA Certificates**.
            2. Locate the Decryption CA Certificate card to renew.
            3. Click **Renew Certificate**.

            A notification appears confirming the renewal.
          </Accordion>

          <Accordion title="Download a Decryption CA Certificate">
            To download a Decryption CA certificate to your local machine:

            1. Go to **Security** > **Distributed Cloud Firewall** > **TLS** > **Decryption CA Certificates**.
            2. Locate the Decryption CA Certificate card to download.
            3. Click **Download Certificate**.
               A notification on your browser appears confirming the download.
          </Accordion>

          <Accordion title="Upload a New Certificate">
            To upload a new certificate:

            1. Go to **Security** > **Distributed Cloud Firewall** > **TLS** > **Decryption CA Certificates**.
            2. Locate the Decryption CA Certificate card to upload.
            3. Click the dropdown next to the **Download Certificate** button and click **Upload New Certificate**.<br />The Upload New Certificate dialog appears.
            4. Upload the Certificate and the Certificate Key.
            5. Click **Upload**.
               A notification appears confirming the upload.
          </Accordion>

          <Accordion title="Upload a New Trust Bundle">
            To upload a new trust bundle:

            1. Go to **Security** > **Distributed Cloud Firewall** > **TLS** > **Decryption CA Certificates**.
            2. Locate the Decryption CA Certificate card to upload.
            3. Click the dropdown next to the **Download Certificate** button and click **Upload Trust Bundle**.<br />The Upload Trust Bundle dialog appears.
            4. Upload the trust bundle file.
            5. Click **Upload**.
               A notification appears confirming the upload.
          </Accordion>

          <Accordion title="Remove a Certificate">
            To remove a certificate:

            1. Go to **Security** > **Distributed Cloud Firewall** > **TLS** > **Decryption CA Certificates**.
            2. Locate the Decryption CA Certificate card to remove.
            3. Click the dropdown next to the **Download Certificate** button and click **Remove Certificate**.<br />The Remove Certificate dialog appears.
            4. Click **Remove**.
               A notification appears confirming the removal.
          </Accordion>

          <Accordion title="Remove a Trust Bundle">
            To remove a trust bundle:

            1. Go to **Security** > **Distributed Cloud Firewall** > **TLS** > **Decryption CA Certificates**.
            2. Locate the Decryption CA Certificate card to remove.
            3. Click the dropdown next to the **Download Certificate** button and click **Remove Trust Bundle**.<br />The Remove Trust Bundle dialog appears.
            4. Click **Remove**.
               A notification appears confirming the removal.
          </Accordion>
        </AccordionGroup>
      </Tab>

      <Tab title="Trust Bundles">
        ### Purpose

        The **Trust Bundles** view lists trust bundles available for TLS operations (including those referenced by TLS profiles and the decryption CA configuration).

        ### Elements

        <Frame>
          <img src={"/images/reference/ui/security/dcf-tls-trust-bundles.png"} alt="Distributed Cloud Firewall: Trust Bundles" width="100%" />
        </Frame>

        * **+ Trust Bundle**: Button to start the workflow for adding a new trust bundle.
        * Trust Bundles table: Displays the list of added trust bundles and their details.
        * **Search**: Filters trust bundle rows in the table.

        ### Actions

        <AccordionGroup>
          <Accordion title="View Trust Bundles">
            To view trust bundles:

            1. Go to **Security** > **Distributed Cloud Firewall** > **TLS** > **Trust Bundles**.
            2. The Trust Bundles page appears with the Trust Bundles table.
            3. Refer to the Parameter Details table for the details of the trust bundles parameters.
            4. Optionally, use **Search** or the table toolbar filters to narrow rows.
               The table displays trust bundles with their name.
          </Accordion>

          <Accordion title="Add a Trust Bundle">
            To upload a trust bundle:

            1. Go to **Security** > **Distributed Cloud Firewall** > **TLS** > **Trust Bundles**.
            2. Click **+ Trust Bundle**.
            3. Enter the name of the trust bundle.
            4. Upload the trust bundle file.
               <Note>**Note:** Ensure the trust bundle file is in .pem format.</Note>
            5. Click **Save**.
               A notification appears confirming the addition.
          </Accordion>

          <Accordion title="Edit a Trust Bundle">
            To edit a trust bundle:

            1. Go to **Security** > **Distributed Cloud Firewall** > **TLS** > **Trust Bundles**.
            2. Locate the trust bundle and click the edit icon in the row.<br />The Edit Trust Bundle dialog appears.
            3. Update the name of the trust bundle and upload new trust bundle file.
            4. Click **Save**.
               A notification appears confirming the update.
               <Note>**Note:** Ensure the trust bundle file is in .pem format.</Note>
          </Accordion>

          <Accordion title="Delete a Trust Bundle">
            To delete a trust bundle:

            1. Go to **Security** > **Distributed Cloud Firewall** > **TLS** > **Trust Bundles**.<br />The Trust Bundles page appears with the Trust Bundles table.
            2. Locate the trust bundle and click the delete icon in the row.
            3. Read the warning message and tick to confirm the deletion.
            4. Click **Delete**.
               A notification appears confirming the deletion.
          </Accordion>

          <Accordion title="Download a Trust Bundle">
            To download a trust bundle to your local machine:

            1. Go to **Security** > **Distributed Cloud Firewall** > **TLS** > **Trust Bundles**.<br />The Trust Bundles page appears with the Trust Bundles table.
            2. Locate the trust bundle and click the Actions icon (⋮) in the row.
            3. Click **Download Trust Bundle**.
               A notification on your browser appears confirming the download.
          </Accordion>
        </AccordionGroup>
      </Tab>
    </Tabs>
  </Tab>

  <Tab title="Settings">
    ## Purpose

    The **Settings** page allows configuration of global firewall settings, logging, and alerting options.

    ## Elements

    <Frame>
      <img src={"/images/reference/ui/security/dcf-settings.png"} alt="Distributed Cloud Firewall: Settings" width="100%" />
    </Frame>

    * **Global Settings Panel**: Configure default action, logging, and alert thresholds.
    * **Notification Settings**: Enable alerts for intrusion detection and policy violations.
    * **Advanced Options**: Configure threat intelligence feeds and update intervals.

    ## Actions

    <AccordionGroup>
      <Accordion title="Configure Global Firewall Settings">
        To configure global firewall settings:

        1. Go to **Security** > **Distributed Cloud Firewall** > **Settings**.
        2. In the **Global Settings Panel**, configure the default action for unmatched traffic.
        3. Set the **Logging Level** (Minimal, Standard, or Detailed).
        4. Configure **Alert Threshold** for triggering alerts.
        5. Save your changes.

        Global settings apply to all Distributed Cloud Firewall policies.

        ### Parameter Details

        | CoPilot Parameter Name | Description                                                  |
        | ---------------------- | ------------------------------------------------------------ |
        | Default Action         | Specifies default action for unmatched traffic (Allow/Deny). |
        | Logging Level          | Sets logging verbosity (Minimal, Standard, Detailed).        |
        | Alert Threshold        | Configures thresholds for triggering alerts.                 |
        | Threat Feed URL        | URL for external threat intelligence feed.                   |
        | Update Interval        | Frequency of threat feed updates.                            |
      </Accordion>

      <Accordion title="Configure Notification Settings">
        To configure notification settings for alerts:

        1. Go to **Security** > **Distributed Cloud Firewall** > **Settings**.
        2. In **Notification Settings**, enable alerts for intrusion detection and policy violations.
        3. Configure notification destinations and preferences.
        4. Save your changes.

        Notifications are sent when configured thresholds or events occur.
      </Accordion>

      <Accordion title="Configure Advanced Options">
        To configure threat intelligence and advanced options:

        1. Go to **Security** > **Distributed Cloud Firewall** > **Settings**.
        2. In **Advanced Options**, configure the **Threat Feed URL** for external threat intelligence.
        3. Set the **Update Interval** for threat feed updates.
        4. Save your changes.

        Threat intelligence feeds enhance intrusion detection and policy enforcement.
      </Accordion>
    </AccordionGroup>
  </Tab>
</Tabs>
