Blocking Anomalies ================== Identify Nodes through Node Group and Block them through New Enforcement Policy ------------------------------------------------------------------------------- You may create a dedicated Node Group and an Enforcement Policy accordingly. Create Anomaly Node Group ''''''''''''''''''''''''' This will group together all Nodes that will be identified by the default Policy using enabled Anomaly Definitions. #. Go to **Policy** in the top panel. #. Go to **Policy > Group > Node** in the left Policy panel. #. Click on **Tasks > Create** #. For **ID:** Unique Name. (*e.g. Anomaly Group*) #. For **Status:** Enabled. #. For **Boolean Operator** select **OR.** #. Find and click on **Add** in **Condition** section. #. For each **Anomaly** you want to add, use the followings: - **Options:** Anomaly - **Operator:** Detected is one of - **Value:** (*One of the listed Anomalies*) #. Click **Add.** #. Keep adding **Conditions** as needed. #. Click **Save.** Create Enforcement Policy To Block Anomalies '''''''''''''''''''''''''''''''''''''''''''' This will block all Anomalies identified within the Node Policy and are listed in the Anomaly Group from Step 1. #. Go to **Policy** in the top panel. #. Go to **Enforcement Policy** in the left Policy panel. #. Click on **Tasks > Create.** #. **Action** tab, click **Next.** #. Under **General** tab: - **ID:** Unique Name. (*e.g. Anomaly Enforcement Policy*) - **Description:** Anomaly Policy to block all Nodes detected as Anomalies. - **Status:** Enabled. - Click **Next.** #. **Node Group** tab, find and double click ** Group** (*e.g. Anomaly Group*) #. **Permission** tab, double click on **PERM-DNS**. Click **Next.** #. **Redirection** tab, click **Next.** #. **Agent Action** tab, click **Finish.** #. Click **Apply.**