Athena NGFW (Next-Generation Firewall)

Athena NGFW (previously known as Network Secure) provides comprehensive protection for every network perimeter, ensuring the safety of your valuable assets, data, and users from emerging threats.
{{ $t('productDocDetail.guideClickSwitch') }}
{{ $t('productDocDetail.know') }}
{{ $t('productDocDetail.dontRemind') }}
8.0.107
{{sendMatomoQuery("Athena NGFW (Next-Generation Firewall)","Scanner Blocker")}}

Scanner Blocker

{{ $t('productDocDetail.updateTime') }}: 2026-02-05

To set behavior detection for a website scan. See the following figure.

Triggers: Specify behaviors to be matched with visit data, based on which scanning behavior is determined. Follow-up processing is also provided. The following describes the behavior characteristics provided currently:

Percentage of 404 errors: It is calculated once every N responses. If the value exceeds the preset value, it is considered that a scanner is scanning the website. You can click Settings to configure the specific frequency and percentage, as shown in the following figure.

Frequent blocks as per WAF rules: Determine whether it is a scanner by judging the times that the Web App Protection rule intercepts a source IP in unit time. You can click Settings to configure the specific frequency, as shown in the following figure.

Frequent access to directories: Determine whether it is a scanner by judging the times that a source IP accesses the directory per second. You can click Settings to configure the specific frequency, as shown in the following figure.

Uncommon HTTP request method: The behavior that triggers the HTTP request method filter rules will be taken as one of the behavioral characteristics of the scanner. You need to enable the method filter.

Match scan rule that hardly causes misjudgment: Match an IP address with a strong scan rule and determine whether it is a scanner.

Match scan rule that easily causes misjudgment: Match an IP address with a strong scan rule and determine whether it is a scanner.

Scan sensitive files: Normally, a scanner will try to access sensitive files on various sites, such as configuration, password, database file, etc. By checking these sensitive files, it can be determined whether an IP address is directed to a scanner.

IP Lockout Duration: When a source IP address is identified as a scanner, it will be blocked for a specified time indicated by this parameter. Data streamed from this source IP address will be blocked during the lockout period when it passes through the Athena NGFW device.

Server Version Hiding: When this function is enabled, the system will intelligently identify and hide the server's version information.

The Scanner Blocker function is not recommended in the following two scenarios:

1. The user's IP address is to undergo source network address translation (NAT).

2. Proxy servers are used to access business.