Host Intrusion Prevention rules determine how to handle network traffic. Each rule provides a set of conditions that traffic must meet and an action to allow or block traffic.
When Host Intrusion Prevention finds traffic that matches a rule’s conditions, it performs the associated action.
Host Intrusion Prevention uses precedence to apply rules:
Host Intrusion Prevention applies the rule at the top of the firewall rules list.
If the traffic meets this rule’s conditions, Host Intrusion Prevention allows or blocks the traffic. It doesn't try to apply any other rules in the list.
If the traffic doesn't meet the first rule’s conditions, Host Intrusion Prevention continues to the next rule in the list until it finds a rule that the traffic matches.
If no rule matches, the firewall automatically blocks the traffic.
.png)
If Adaptive mode is activated, an Allow rule is created for the traffic. Sometimes the intercepted traffic matches more than one rule in the list. In this case, precedence means that Host Intrusion Prevention applies only the first matching rule in the list.
Important
Place the more specific rules at the top of the list, and the more general rules at the bottom. This order makes sure that Host Intrusion Prevention filters traffic appropriately.