Chapter 5 Monitor
USG FLEX H Series User’s Guide
73
The following table describes the labels in this screen.
5.7.3 URL Threat Filter
This screen displays URL threat filter statistics. URL threat filtering compares access to specific URLs
against a database of blocked or allowed sites.
Table 36 Security Statistics > Reputation Filter > DNS Threat Filter
LABEL DESCRIPTION
Last 24 Hours Summary
Top Entries By Use this field to have the following (read-only) table display the top DNS threat filter log
entries by Category, Source IP or DNS Name. This table displays the most common,
recent DNS threat filter logs. See the log screen for less common DNS threat filter logs or
use a syslog server to record all DNS threat filter logs.
Select Category to list the most common categories of packets that the Zyxel Device has
detected.
Select Source IP to list the most common source IP addresses of traffic.
Select DNS Name to list the most common FQDNs of the infected websites.
Refresh Click this button to update the report display.
Flush Data Click this button to discard all of the screen’s statistics and update the report display.
DNS Threat Filter Events
Time This field displays the date and time the entry was created.
+ Allow List Select an entry and click this to add it to the DNS filtering allow list.
DNS Name This field displays the FQDN of an infected website.
Category This field displays the category of the entry.
Source IP This field displays the source IP address of traffic that you want to trace.
Apply Click Apply to save your changes back to the Zyxel Device.
Reset Click Reset to return the screen to its last-saved settings.