Skip to main content

Use network activity

The Network Activity page shows observed network flows and traffic patterns across your firewalls. Use it to explore what's happening on your network, identify unknown or unwanted traffic, and create firewall rules directly from what you see.

warning

When discovery mode is enabled on an interface, the firewall allows all traffic through, regardless of any rules configured for that interface. Discovery mode can run indefinitely. You decide when you've seen enough traffic, then disable it to begin enforcing rules.

Network activity grid view

Filter network flows​

Use the search and filter fields at the top of the page to narrow down the flow list:

FilterFilter by
Time rangeDate/time window for observed flows (defaults to Past Day; click the calendar icon to change it)
Source FirewallFirewall name
Source InterfaceInterface name (e.g., ens5)
Source AddressSource IP address or subnet
Destination AddressDestination IP address or subnet
Destination PortPort number or range
ProtocolProtocol (TCP or UDP)

Combine filters to isolate specific traffic for analysis or rule creation.

Table columns​

Each flow row includes:

ColumnDescription
DirectionWhether the flow is INGRESS (into the firewall) or EGRESS (out of the firewall)
TXBytes transmitted for the flow
RXBytes received for the flow
ConnectionsTotal number of connections observed for the flow

Switch between grid and roll-up view​

By default, the page shows the Grid View, which lists each flow individually. To group flows by firewall, click the View icon at the top right of the table to switch to Roll-Up View. Click it again to return to grid view.

Network activity view icon

Roll-up view makes it easier to spot patterns and high-level trends across many flows.

Create a rule from a discovered flow​

You can create a rule from a specific flow, or open a blank rule from the toolbar.

  1. On the Network Activity page, find the flow you want to allow or block.

  2. Click the Create rule icon in that row's Create Rule column.

    Alternatively, click the + Create Rule button at the top right of the filter bar to open a blank rule.

    The rule creation dialog opens, pre-filled with the source, destination, port, and protocol from that flow (or blank if opened from the toolbar).

  3. Adjust the rule details as needed and set the action to Allow or Block.

  4. Click Done to save the rule. It becomes active immediately and appears in your firewall's rule set.

Network activity create rule

For more on managing rules, see Manage firewall rules.