Exium Intrusion Detection System (IDS) activates automatically when security is enabled on your device, providing continuous monitoring of network traffic for known threats, suspicious activity, and policy violations. Managed through the Security Cloud, IDS policies and signature updates stay current without manual intervention, while detected events are logged and made available in Insight for visibility and analysis.
Setup and configuration:
- Log in to Insight at insight.netgear.com
- Select the Organizations tab, and click the name of the organization.
- Select the Security Center tab, and click the Security Configurations button. The Exium Security page displays.
- From the left menu, click Sites > Local Policies > IDS/IPS.
- From the dropdown menu, select the PR60X/PR460X.
- Enable and update configuration as necessary.
Monitoring and maintenance:
- From the menu on the left, click XDR > Login.
- In the Actions column of the table, click the profile icon.
- In the Wazuh login page, enter the user name and password that display at the top of the screen, and click the Log in button.
- Click the Threat Hunting tile, and click the Add filter link.
- In the Edit filter pop-up window, from the Field menu, select rule.groups, and from the Operator menu, select is.
- Click the Save button.
- Select the Events tab, and click the explore icon next to each event to see event details.
- To narrow the alerts for a specific router or site, click the Add filter link again.
- In the Edit filter pop-up window, from the Field menu, select agent.name.
- From the Operator menu, select is, and from the Value menu, select your site.
- Click the Save button.
For more information on IDS, see Intrusion Detection and Prevention Systems.