Skip to content

Block IP

Block IP

Purpose

The Block IP page allows SOC to block malicious or suspicious IP addresses, integrated with firewall/WAF/IDS when available.

Key Features

  • List of blocked / unblocked IPs with metadata (office, agent, reason, created_by, expires).
  • Actions: Block, Unblock, View, Delete.
  • Can integrate with firewall, WAF, or IDS/IPS systems.

How to Use

  1. Select Office and (optionally) Agent.
  2. Enter IP Address or paste from event.
  3. Select Block or Unblock and record the reason.

If you need to view details of an action, click on Actions → View. If you want to delete, select Actions → Delete.

Notes

  • Before mass blocking, check for impact on the system (false-positive).
  • Use SOAR to automate blocking according to tested policies.