General Settings

  1. Go to Policy and expand a policy profile.
  2. Click any one of these:
    • Device

    • Application

    • File

    • Network

  3. Click Network Protection > General Settings and set these parameters:
    Item Description Value
    Network Protection Enable or disable On-device Network Protection (ONP) through VPN.
    • OFF - Disables ONP.

    • Always ON - Enables ONP by default. To configure this behavior, go to Configure > Advanced Configuration.

    • Turn ON when a device is at High risk - Enables ONP automatically when the device's risk level changes to High. It is turned off automatically when the device's risk level is lowered to Medium or Low.

    Network Protection Working Mode

    Set the ONP working mode.

    This setting is active only if the Network Protection is set to Always ON or Turn ON when a device is at High risk.

    • Full inspection (Default) - Enables ONP for the entire device network traffic.

    • Browser only - Enables ONP for specific browsers only.

      To select the browsers, go to Browser Only Settings.

    • Detect mode - Evaluates ONP before you enable it on the user device. Monitors the device traffic and does not block malicious traffic. If malicious traffic is detected, it is logged in Forensics > Events & Alerts.

      Detect Mode is not supported for Zero-day Phishing Detection and File Protection.

    • Proxy mode - Enables ONP for web traffic (example, HTTP and HTTPS).

    Tip:

    We recommend to use Detect mode for a certain period to only monitor traffic and identify malicious content. After this period, you must use the Full inspection or Browser only mode to block malicious traffic automatically.

    Network Protection not installed Set the device risk status when ONP is not installed.
    • Medium (Device Alert) (Default)

    • High (Device Alert)

    • Medium (Device Alert)

    • Medium (No Device Alert)

    • Medium (Dismissive Device Alert)

    • Low

    • No Risk

    Event severity level Set the risk level for ONP generated events.
    • Information (Default)

    • Critical

    • Warning

    • Information

    Show device notifications Indicates whether to show device notification if a network resource is blocked. N/A
    Use next generation ONP Enables the next generation ONP for iOS. For more information on the new ONP, see sk183634. When you enable this option, the next generation ONP replaces the legacy ONP.

    The table below lists the features available for the configured Network Protection Working Mode:

    Feature Full inspection Browser only
    Anti-Bot Yes No
    Phishing Yes Yes
    Zero phishing Yes Yes
    File download prevention Yes Yes (except Safari extension)
    MiTM detection Yes Yes
    Safe DNS (aka Protected DNS) Yes No
    Block app traffic (on Android) Yes No
    Content filtering (aka URLF) Yes Yes
    Port scan detection Yes No
    Zero-Touch support Yes Yes (except Safari extension)
    Network Protection snooze by user Yes No
    Conditional access Yes Applicable only to web traffic.