Athena NGFW (previously known as Network Secure) provides comprehensive protection for every network perimeter, ensuring the safety of your valuable assets, data, and users from emerging threats.
To analyze a source IP address, destination IP address, or domain name, and obtain matching details of traffic to locate the traffic precisely. It is recommended to select this method when some users cannot access the Internet, or some services or applications cannot be used. You must enter the source IP address or destination IP address/domain name for directional analysis to rapidly locate fault causes.
Src IP and Dst IP/Domain: Enter one or both of the source IP address and destination IP address of a packet for precise matching.
Protocol: Specify the protocol of the packet that can be output to the analysis result list. You can select All, TCP, UDP, ICMP, ICMPv6, and other protocols for this parameter.
Passthrough: Specify whether the policy is allowed for the matched packet.
Status: Specify whether the matched packet is Denied or Allowed to be output to the analysis result list. You can select Denied for this parameter when troubleshooting the problem that some users cannot access the Internet.
Validity Period: Set the validity period for the Precise Traffic Analysis.
Packets to Analyze: Set the number of data packets to be captured and analyzed by the system. The value range is between 100-300.
Obtain analysis results:This option is not recommended when the Validity Period is set to Always. The Obtain analysis results will generate numerous logs and cause high device performance consumption.
After you click Turn On, the matching details will be displayed in the analysis result list. See the figure below.
Click Refresh to view the packet's matching situations in real time.
Click Reset Logs to clear all the existing logs and analyze the packets again.
Click View to see the specific policy matching with this packet. See the figure below.
After the troubleshooting is completed, click Turn Off. This makes the address policy specified to the passthrough rule continue to take effect.