You can configure alert settings to define mistakenly-denied access alerts. When legitimate business traffic is mistakenly blocked by distributed firewall policies, an alert will be triggered to notify administrators to adjust the policies.
Constraints and Restrictions
• Alert settings take effect only for resource pools running HCI 6.10.0 or later.
Alerts can be associated with only built-in services, not custom services.
Precautions
• Configure alert thresholds based on actual business traffic patterns to avoid false positive alerts or false negative alerts. (For example, higher alert thresholds are recommended for services with high-frequency access.)
• After alert-associated services are changed, save the alert settings again. Otherwise, the changes cannot take effect.
Steps
Step 1.Step 1: Log in to SCP and go to Networking > Network Insight > Settings > Alert Settings.
Step 2.Step 2: Configure the thresholds for Access Denied Frequently. (Example: Within 5 minutes, access from one IP address is denied over 10 times.)
Step 3.Step 3: Click View Associated Services to add or remove services (such as SSH and HTTP services) to be monitored.
Step 4.Step 4: After the configuration is complete, click Save to apply the settings.
Field Description and Operation Suggestion
Field
Description
Operation Suggestion
Access Denied Frequently - Time Window (minutes)
Specify the time window during which a large number of access attempts are denied.
Configure this field based on business traffic density. It is recommended to set it to 5-10 minutes for services with high-frequency access and 1-3 minutes for services with low-frequency access.
Access Denied Frequently - Deny Count
Specify the number of access attempts denied within the time window.
Configure this field together with the time window to accurately identify anomalies (Example: 10 denied attempts within 5 minutes).
Service Associated with Alerts
Select services to be monitored from the list of built-in services.
Select business-related services. (For example, select the HTTP service for OA systems and the MySQL service for databases.)