Manage ThreatSync+ NDR Zones

Applies To: ThreatSync+ NDR

This feature is only available to participants in the ThreatSync+ NDR Beta program.

Policies in ThreatSync+ NDR are tied to network zones. Policies use zones to identify a set of sources and destinations used to filter traffic. A zone can be a group of IP addresses, assets, organizations, countries, domains, or localities. Zones are classified as either Internal or External.

On the Manage Zones page, you can view a list of all the zones in your network. This list includes default zones and zones you add manually. For more information about default zones, go to Default Policies and Zones.

Screenshot of the Manage Zones page in ThreatSync+ NDR

The zone list shows these columns:

  • Type — The type of zone. For example, internal or external devices.
  • Name — Name of the zone. Click the zone name to view details of the zone.
  • Description — A description of the zone that includes guidance about how the zone is detected.
  • Display Alerts By — How policy alerts are organized and presented on the Policy Alerts and Policy Alerts Details page. For example, if you select country in a destination zone, the policy alerts are grouped by country that the traffic was directed to, and the policy alerts and charts are also grouped by country.
  • Members — Members of the zone. For example, members can include domains by name, or devices with a specific tag.

Add a ThreatSync+ NDR Zone

To add a custom zone, from WatchGuard Cloud:

  1. Select Configure > ThreatSync+ NDR > Zones.
    The Manage Zones page opens.
  2. Click Create a Zone.
    The Create a New Zone page opens.
  3. In the Name and Description section, in the Zone name text box, enter a name for your zone.
  4. In the Description text box, enter a description.
  5. Click the Zone Definition section to expand it.
  6. Select either Devices on my Internal Network or Devices External to my Network.
  7. From the Display Alerts by drop-down list, select a category to organize and present your policy alerts.
  8. Select Begin with an Empty Zone, Begin with a zone containing all Internal Devices (if you selected Devices on my Internal Network in Step 6), or Begin with a zone containing all External Devices (if you selected Devices External to my Network in Step 6).
  9. Click Add Rule.
    The Create Rule dialog box opens.

Screenshot of the Create rule dialog box in the Create a new zone wizard

  1. Select one of these options from the drop-down list:
    • Countries
    • Domains
    • IPs
    • Localities
    • Organizations
  2. Select either Includes or Excludes.
  3. Enter the rule properties to include or exclude. For example, for a domain, enter a website address.

Screenshot of a Domains rule example that shows a website address (www.example.com) added to the rule

  1. Click The Add icon. To add another value to this Includes or Excludes rule, enter the value and click The Add icon again.
  2. Click Add.
  3. Click Save.

Edit a ThreatSync+ NDR Zone

You can edit a zone that you added manually or edit a default zone.

When you edit a default zone, WatchGuard Cloud saves a new copy of the zone with your changes, and all policies that used the original default zone now use the new copy. If you delete the copy, the changes you made to the zone definition are discarded and the zone reverts back to the original default zone. This affects the operation of all policies that use that zone.

System upgrades can make changes to default zones. If you have not made any edits to default zones, system upgrades that change default zones will affect your account. However, If you have edited a default zone, any updates to the definition of the original default zone are not visible in your account until you delete your copy.

To edit a ThreatSync+ NDR zone:

  1. On the Manage Zones page, click The Edit icon next to the zone you want to edit.
    The Edit Zone page opens with the Manage tab selected by default.
  2. On the Overview tab, you can view a summary of the zone details.
  3. On the Manage tab, you can make changes to the zone definition or associated rule.
  4. Click Save.
  5. The Policies tab shows a list of policies used by the zone. Click The Edit icon to edit the policy, or click New Policy to add a new policy.

For more information, go to Configure ThreatSync+ NDR Policies.

Related Topics

About ThreatSync+ NDR Policies and Zones

Policy Tuning