SonicOS 7.1 Security Services

Configuring Botnet Filtering

To configure Botnet filtering

  1. Navigate to POLICY | Security Services > Botnet Filter.
  2. Click Settings.
  3. To block all servers that are designated as Botnet command and control servers, select the Block connections to/from Botnet Command and Control Servers option. All connection attempts to/from Botnet command and control servers will be blocked. This option is not selected by default.

    If this option is selected, the radio buttons and the Block all connections to public IPs if BOTNET DB is not downloaded option become available.

    To exclude selected IPs from this blocking behavior, use exclusion lists as described in the following steps and/or create a custom Botnet list as described in Creating Custom Botnet Lists.

  4. If Block connections to/from Botnet Command and Control Servers is selected, these options become available:
    1. Select one of the following two modes for Botnet Filtering:
      • All Connections: All connections to and from the firewall are filtered. This is the default Botnet block mode.
      • Firewall Rule-Based Connections: Only connections that match an access rule configured on the firewall are filtered.
    2. If you want to block all connections to public IPs when the Botnet database is not downloaded, select the Block all connections to public IPs if BOTNET DB is not downloaded. This option is not selected by default.
  5. To enable the Custom Botnet List, select Enable Custom Botnet List. This option is not selected by default.

    If Enable Custom Botnet List is not selected, then only the Botnet database that resides on the network security appliance is searched. Go to Step 6.

    Enabling a custom list by selecting Enable Custom Botnet List can affect country identification for an IP address:

    1. During Botnet identification, the custom Botnet list is searched first.
    2. If the IP address is not resolved, the firewall’s Botnet database is searched.

    If an IP address is resolved from the custom Botnet list, it can be identified as either a Botnet IP address or a non-Botnet IP address, and action taken accordingly.

  6. Select Enable logging to log Botnet Filter-related events.
  7. Optionally, you can configure an exclusion list of all IPs belonging to the configured address object/address group. All IPs belonging to the list are excluded from being blocked. To enable an exclusion list, select an address object or address group from the Botnet Exclusion Object list.

    The default exclusion object is Default Geo-IP and Botnet Exclusion Group. You can create your own address object or address group object.

  8. Click Accept.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden