Response Integration Blocks

Formerly named Traffic Manager, the Response Integration Blocks page is part of the Detection & Response options in the Netography Fusion Platform portal. This page provides an overview of the traffic management statistics, including block rates and top destinations, as well as a detailed table of traffic data.

Widgets

The following widgets are displayed on the Response Integration Blocks screen:

  1. Current Blockrate (bps): Displays the current block rate in bits per second.
  2. Total Blocks: Shows the total number of blocks recorded.
  3. Blockrate: Presents the block rate calculated at 30-minute intervals.
  4. Top Destination Protocols: Lists the top destination protocols based on traffic volume.
  5. Top Destination Ports: Shows the most frequently used destination ports.

Traffic Data Table

The Response Integration Blocks screen also features a table with the following columns:

  • ALL: A checkbox to select all, checked, or unchecked values for filtering.
  • Start: The start time of the traffic event.
  • Expiration: A dropdown to filter traffic events based on expiration status: all, not expired, or expired.
  • Active: A dropdown to filter traffic events based on their active status: all, active, or inactive.
  • srcip: The source IP address of the traffic.
  • srcipname: A dropdown to filter traffic events by source IP name.
  • srciprep.categories: A dropdown to filter traffic events by source IP reputation categories.
  • srcgeo: The geographic location of the source IP.
  • dstas.number: The destination Autonomous System (AS) number.
  • dstas.org: The organization associated with the destination AS.
  • dstip: The destination IP address of the traffic.
  • dstipname: A dropdown to filter traffic events by destination IP name.
  • rules: The rules applied to the traffic event.
  • adapter: The network adapter used for the traffic event.
  • plugin.name: The name of the plugin associated with the traffic event.
  • dstgeo: The geographic location of the destination IP.

Use the Response Integration Blocks screen to monitor and analyze traffic patterns, identify potential security threats, and gain insight into your network's performance. You can apply filters to the data table to focus on specific events or narrow down your analysis.

Layout options

On the top left hamburger button under the Active Blocks heading, you can export your Response Integration Blocks layout results in your current view, or all fields. You can also configure the layout options by toggling the switches for each column.