Skip to main content

Use network discovery

The Network Discovery page shows observed network flows and traffic patterns across your firewalls. Use it to explore what's happening on your network, identify unknown or unwanted traffic, and create firewall rules directly from what you see.

warning

When discovery mode is enabled on an interface, the firewall allows all traffic through, regardless of any rules configured for that interface. Discovery mode can run indefinitely. You decide when you've seen enough traffic, then disable it to begin enforcing rules.

Network discovery grid view

Filter network flows

Use the search and filter fields at the top of the page to narrow down the flow list. You can filter by any column:

ColumnFilter by
SourceFirewallFirewall name
SourceInterfaceInterface name (e.g., eth0)
SourceAddrSource IP address or subnet
DestinationAddrDestination IP address or subnet
DestinationPortPort number or range
ProtocolProtocol (TCP or UDP)

Combine filters to isolate specific traffic for analysis or rule creation.

Switch between grid and roll-up view

By default, the page shows the Grid View, which lists each flow individually. To group flows by firewall, click the View icon at the top right of the table to switch to Roll-Up View. Click it again to return to grid view.

Network discovery view icon

Roll-up view makes it easier to spot patterns and high-level trends across many flows.

Create a rule from a discovered flow

  1. On the Network Discovery page, find the flow you want to allow or block.

  2. Click the Create rule icon next to the flow.

    The rule creation dialog opens, pre-filled with the source, destination, port, and protocol from that flow.

  3. Adjust the rule details as needed and set the action to Allow or Block.

  4. Click Done to save the rule. It becomes active immediately and appears in your firewall's rule set.

Network discovery create rule

For more on managing rules, see Manage firewall rules.