---
title: Protection Overview
slug: protection-overview
docTags: 
createdAt: 2026-01-14T08:01:16.859Z
---

## Overview

The **Protection** section is the central command center for your network security. Here, you define the logic that determines which websites are accessible, which threats are blocked, and how specific exceptions are handled.

To access this section, navigate to **Protection** in the main sidebar. The menu is divided into three key areas:

## Policies

Policies are the heart of your filtering system. A **Policy** is a container that bundles all your filtering rules (Malware, Content, GeoBlocking, etc.) into a single object.

Instead of configuring every network individually, you create a Policy (e.g., "Guest Wi-Fi" or "Office Staff") and assign it to as many networks as needed.

- **Standard Policies:** Fully customizable profiles where you control every security layer.
- **Restricted Policies:** Locked-down profiles with pre-set security rules, ideal for strict compliance.

:::hint{type="info"}
**Learn how** to create, configure, and assign security profiles: [Policies](docId\:i3Yd_tV8604vQf9JT7_CC)
:::

## Exceptions

While Policies handle broad categories (like "Block Social Media" or "Block Malware"), **Exceptions** handle specific domain names.

Use this section to create granular overrides that supersede your Policy rules:

- **Allow List (Whitelist):** Ensure a specific domain (e.g., partner-company.com) is always accessible, even if its category is blocked.
- **Block List (Blacklist):** Block a specific domain (e.g., distracting-game.com) even if its category is allowed.

:::hint{type="info"}
**Learn how** to manage global and policy-spcific allow/block lists: [Exceptions](docId\:qOIz3D3hjLLYPQcWHto8O)&#x20;
:::

## Templates

Located in the sidebar under Exceptions, **Templates** allow you to save sets of settings to be reused across multiple policies or organizations. This is particularly useful for MSPs or large organizations that need to deploy standard configurations quickly.

:::hint{type="info"}
**Learn how** to create and manage reusable configuration settings: **Soon**
:::

## How the Protection Flow Works

To secure a network, follow this logical workflow:

1. **Create a Policy:** Define your rules for Malware, Content, and Applications.
2. **Assign the Policy:** Apply this profile to your desired Networks or Groups.
3. **Manage Exceptions:** If a legitimate site is blocked (or a bad site gets through), add it to the Exceptions list to fine-tune the filter without changing the entire policy.
