Threat Blocker or the firewall's threat intelligence
Many firewalls already come with the vendor's threat intelligence service. What Threat Blocker adds, what it does not do, and when to use both.
In short
The two are not exclusive: in parallel mode Threat Blocker adds its list of malicious IPs to the rules of the firewall you already use.
Threat Blocker
- You have firewalls from different vendors, or several sites, and want the same list of malicious IPs everywhere.
- Your firewall has no active threat intelligence subscription.
- You want to see the blocks in Cyber Console, next to controls and compliance.
- A small site without a firewall needs a device that acts as one.
The firewall's threat intelligence
- You have a single vendor and its full security bundle: IPS signatures, web filtering, sandbox.
- You need to block categories of sites or single URLs: Threat Blocker blocks IP addresses.
Point by point
| Criterion | Threat Blocker | The firewall's threat intelligence |
|---|---|---|
| What it blocks | Threat BlockerConnections to and from malicious IP addresses, inbound and outbound | The firewall's threat intelligenceDepends on the vendor and licence: often IPs, web categories, IPS signatures |
| Source of the indicators | Threat BlockerOur threat intelligence | The firewall's threat intelligenceThe firewall vendor's service |
| Compatibility | Threat BlockerFirewalls that read an external list of IP addresses, or in place of the firewall | The firewall's threat intelligenceOnly that vendor's devices |
| Several sites or vendors | Threat BlockerThe same list for every firewall | The firewall's threat intelligenceOne service per vendor |
| Domains, URLs and files | Threat BlockerChecks from Cyber Console and our APIs, not blocked by the device | The firewall's threat intelligenceDepends on the licence: web filtering, sandbox |
| Visibility | Threat BlockerIn Cyber Console: blocks, top sources by country, an exportable access log | The firewall's threat intelligenceIn the firewall's console |
| Without a firewall | Threat BlockerIn series mode the device is the firewall | The firewall's threat intelligenceNeeds the firewall |
| Updates | Threat BlockerAutomatic, at least once an hour | The firewall's threat intelligenceAutomatic, while the licence is active |
Getting started with Threat Blocker
-
1
Mode
We decide together whether to install it in parallel, next to the firewall, or in series, in its place.
-
2
Device
We prepare the device and connect it to your network.
-
3
Rules
In parallel mode, the firewall reads the list of malicious IPs and sends its logs to the device.
-
4
Cyber Console
Blocks and device status are visible in Cyber Console.
Frequently asked questions
Only if you install it in series. In parallel it works next to the firewall you already use, and the firewall applies the block.
Those that can read an external list of IP addresses and send logs over syslog. We check your model before installation.
No, it blocks IP addresses. Domains, URLs and files can be checked from Cyber Console and through our APIs.
Automatically, at least once an hour, with nothing for you to do.
Other comparisons
Cloud Defender or a traditional WAF
Cloud Defender and an in-house WAF compared: activation, maintenance, rules, DDoS, direct access to the server and visibility.
Full comparisonNIS 2 in house or with Cyber Console
Running NIS 2 on spreadsheets, folders and email or with Cyber Console: answers, history, evidence, activities, documents and audits compared.
Full comparisonNot sure yet which fits you?
The Cyber Check-up returns your company's cyber profile and the priorities to start from.