Skip to main content

Firewall Audit and Quarantine Capability

Using Nexus Repository 3.94.0+? Check out our updated workflow

This page describes the Firewall capability configuration workflow used for Nexus Repository versions before 3.94.0. From Nexus Repository 3.94.0 forward, Firewall is configured at the repository level by using Firewall Modes.

For the current workflow, see Firewall Configuration for Nexus Repository.

The Repository Firewall configuration may be managed by setting the Firewall Audit and Quarantine capability for each proxy repository that will need to be protected.

Adding the Audit and Quarantine Capability

  1. Log in to Nexus Repository Pro 3 with Administrator credentials.

  2. Go to SettingsSystemCapabilities.

  3. Select Create Capability.

  4. Under Select Capability Type, select Firewall Audit and Quarantine.

    Select_Capability_Type.png
  5. From the dropdown list, select the repository to configure with the Repository Firewall.

  6. Select the Enable Quarantine for Repository checkbox and click Create Capability button.

    Create_Capability.png

The audit on the selected repository starts automatically. Nexus Repository connects to the IQ Server and evaluates the components within the selected repository against any associated policy.

The Quarantine option is required to protect your repository from critical threats. By default, only malicious components are quarantined; these should never be allowed in your repository. You have control over the Repository Firewall's enforcement using actions on your IQ Server policies.

See Managing the Quarantine

Disabling the Audit and Quarantine Capability

Disabling quarantine will release all quarantined components to your proxy repository. Previously quarantined components are not quarantined again. Only new components are evaluated for quarantine when quarantine is re-enabled.

To disable Audit and Quarantine:

  1. In Nexus Repository, navigate to the Settings menu and select Capabilities under System.

  2. Select the Firewall Audit and Quarantine capability for the target repository.

  3. Select Disable. It disables the quarantine capability as well.

  4. To disable only quarantine, go to the Settings tab and deselect the Enable Quarantine for Repository checkbox.

    Disable_Firewall_Audit_and_Quarantine.png
  5. Select Save.