Advanced IP Defense in Command Center
Focus
Focus
Advanced IP Defense

Advanced IP Defense in Command Center

Table of Contents

Advanced IP Defense in Command Center

Use the Command Center in Strata Cloud Manager to monitor Advanced IP Defense threat counts, severity breakdowns, and policy alerting trends.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Advanced IP Defense license
  • Log forwarding to Strata Logging Service configured
The Command Center in Strata Cloud Manager provides an executive-level overview of your security posture across all cloud-delivered security services. Advanced IP Defense appears as a dedicated node in the Command Center Threat View alongside Advanced Threat Prevention, Advanced DNS Security, Advanced WildFire, and Advanced URL Filtering.
To access Advanced IP Defense in Command Center, select DashboardsCommand Center in Strata Cloud Manager, then navigate to the Threat View. The Advanced IP Defense node provides an at-a-glance summary of your IP-based threat posture.

Advanced IP Defense Threats Summary

The Advanced IP Defense summary card displays the following metrics for the selected time range (last 7 days or last 30 days):
  • Total threats—The total number of connections that matched Advanced IP Defense policy rules.
  • Blocked threats—Connections that were blocked by a policy rule with the action set to Block or Deny.
  • Alerted threats—Connections that were logged but allowed by a policy rule with the action set to Alert.
The summary card includes a trend indicator that compares the current period against the prior period, helping you identify increases or decreases in IP-based threat activity.

Alerted Threats by Severity

The Command Center breaks down alerted threats by severity level (Critical, High, Medium, Low, and Informational). This ranked list helps you prioritize investigation by focusing on the highest-severity alerts first. For each severity level, you can see the count of alerted threats and the top 5 security rules that allowed those threats, helping you identify policies that may need stricter enforcement.

Top Policies Alerting Threats

This view shows the security policy rules that are generating the most Advanced IP Defense alerts. Rules that appear frequently in this list may indicate candidates for changing the action from Alert to Block, or may require additional investigation to determine whether the alerted traffic is legitimate or malicious. Use this information to iteratively tighten your Advanced IP Defense enforcement posture.

Executive Summary

Advanced IP Defense also appears on the Executive Summary page as a security subscription card. The subscription card displays the overall status of your Advanced IP Defense deployment, including whether the subscription is active and the total threat count for the current period. This provides a quick health check for executives and security operations teams who need a high-level view without drilling into individual threat details.