Last adaptation to the version: 2.14 (02.2026)
- New profile tab: Cloud Shield
notemptyThis article refers to a Beta version
Function description
Profiles allow several UTMs to assign specific events.
Initially, there is the option to perform an automatic update when a new version is available on the UTM.
Overview
Profiles
| Add profile | Creates a new profile. Existing profiles can be edited by clicking on the profile tile. | |||||||
General General - Local profiles
Local profiles | ||||||||
| Caption | Value | Description | ![]() | |||||
|---|---|---|---|---|---|---|---|---|
| Name | select attribute | Select which attribute should be used as the device name to identify the devices in the Cloud Shield statistics and logs. | ||||||
| Priority | 5Default | The higher the number, the higher the priority. This is only used if a device is assigned to multiple profiles. | ||||||
| Cross-tenant profile | Remains disabled for local profiles | |||||||
| UTMs | Add UTMs | Available UTMs can be selected in the clickbox | ||||||
| Tags | Add tags | The profile is assigned to all UTMs that have at least one of these tags notemptyOn UTMs from version 14.1.0, the permission to set certain values can be revoked via the profiles. In this case, settings from the profiles are not implemented on the UTM. | ||||||
| Comment | Comment | Comment field for additional descriptions | ||||||
Cross-tenant profiles General - Cross-tenant profiles
In the tenants themselves, a copy of these profiles is displayed with the feature Generated. The copy cannot be edited. Editing is only possible in the profile in which it was created. | ||||||||
| Caption | Value | Description | ![]() | |||||
| Name | select attribute | Select which attribute should be used as the device name to identify the devices in the Cloud Shield statistics and logs. | ||||||
| Priority | 5 | The higher the number, the higher the priority. This is only used if a device is assigned to multiple profiles. | ||||||
| Cross-tenant profile | This profile affects the active tenant (reseller or parent company) and all subsequently selected clients | |||||||
| Tenants | Select tenants | Tenants to which the profile in addition to the own tenant is to be applied | ||||||
| Select all | Adds all tenants | |||||||
| Tags | Add tags | The profile is applied to all UTMs with this tag across all tenants. | ||||||
| Comment | Comment | Comment field for additional descriptions | ||||||
Cloud-Backup Cloud-Backup
| ||||||||
| Caption | Value | Description | ![]() | |||||
| Manage Cloud Backup | Allows configuration of cloud backup settings when activated | |||||||
| Activate Cloud Backup on the UTM | If activated , a time frame can be specified in which the boot configuration of the UTM is saved on a Securepoint cloud server. notemptyThese settings can only be applied to UTMs from version 12.6.2. | |||||||
| Daily from: xx o'clock | 00:00 | Setting the time at which the cloud backup starts. | ||||||
| Password | Password | Password required to restore the backup | ||||||
Server settingsServer settings
| ||||||||
| notemptyThese settings can only be applied to UTMs from version 12.6.2. | ||||||||
Firewall | ||||||||
| Caption | Value | Description | ![]() | |||||
| Manage Firewall | Allows configuration of firewall settings when activated | |||||||
| Global contact person | The name of the administrator or organization is entered in this field, which is later specified in the UTM error messages for queries. | |||||||
| Global email address | Important system messages are sent to this email address. The email address entered must be correct. | |||||||
| Language of the reports | German | The important system messages are sent in this language. Alternatively, English can also be selected. | ||||||
DNS-Server | ||||||||
| Caption | Value | Description | ![]() | |||||
| Manage DNS server | Allows configuration of the DNS server settings when activated | |||||||
| Check nameserver before local cache | The local cache of the UTM first answers the DNS queries (corresponds to 127.0.0.1 as the primary name server. When activated, the name servers entered here will check the name resolution before the local cache of the UTM. | |||||||
| Primary nameserver | IPv4/IPv6 | The IP addresses of two external nameservers to which the UTM should forward the DNS queries can be entered here. notemptyPlease do not enter a DNS server from your own internal network. | ||||||
| Secondary nameserver | IPv4/IPv6 | The IP addresses of two external nameservers to which the UTM should forward the DNS queries can be entered here. notemptyPlease do not enter a DNS server from your own internal network. | ||||||
Time settings | ||||||||
| Caption | Value | Description | ![]() | |||||
| Manage time | Allows configuration of the time settings when activated | |||||||
| NTP-Server | Add NTP servers | The desired NTP servers can be entered here. | ||||||
| Time zone | Europe/Berlin | The time zone in which the UTM is located. | ||||||
Administration | ||||||||
| Caption | Value | Description | ![]() | |||||
| Manage administrations settings | Allows configuration of the administration settings when activated | |||||||
| Enable administrative access for: | Add administrators | Host names, IP addresses and networks can be enabled for administration. The network with the "internal" zone is always enabled. | ||||||
Global GeoIPGlobal GeoIP
| ||||||||
| Caption | Value | Description | ![]() | |||||
| Manage GeoIP | Allows configuration of the GeoIP settings when is activated notemptyThese settings can only be applied to UTMs from version 12.6.2. | |||||||
| Activate source GeoIP blocking | If activated {ButtonAn | |||||||
Sources | ||||||||
| System-wide rejected sources |
| |||||||
| Select all Deselect all | ||||||||
| Exceptions | IPv4/IPv6 | IPs stored here are excluded from source GeoIP blocking. | ||||||
| Activate target GeoIP blocking | If activated the GeoIP settings for rejected destinations is active | |||||||
Destinations | ||||||||
| System-wide rejected destinations |
| |||||||
| Select all Deselect all | ||||||||
| Exceptions | IPv4/IPv6 | IPs stored here are excluded from the destination GeoIP blocking. | ||||||
Global VPN-SettingsGlobal VPN-Settings
| ||||||||
| Caption | Value | Description | ![]() | |||||
| Manage global VPN | When activated allows the configuration of the global VPN settings notemptyThese settings can only be applied to UTMs from version 12.6.2. | |||||||
| Primary nameserver | IPv4/IPv6 | Primary nameserver which is used for the VPN tunnel clients. | ||||||
| Secondary nameserver | IPv4/IPv6 | Secondary nameserver which is used for the VPN tunnel clients. | ||||||
Firmware-Updates Firmware-Updates
| ||||||||
| Caption | Value | Description | ![]() | |||||
| Firmware update settings | If activated, the firmware update settings can be defined. | |||||||
| Activate automatic updates on the UTM | Upon activation , a timeframe can be specified in which updates will perform automatically.
It is possible that one UTM may already have an update while another UTM in the same network has not yet received one.
| |||||||
| Period | Mo Di Mi Do Fr Sa So | Selection of the weekdays on which an update can be performed notemptyThe option 1x per month is not available on the UTM and is therefore no longer displayed here. If the option was previously used, it will continue to be used until a change is made in the firmware update area in the portal or on the UTM from v12.6.2. | ||||||
| From 00:00 (UTC) | Time period within which an update should be performed, if applicable The update is triggered by the portal. For better load balancing, only one time period can be selected within which the process is started. | |||||||
Additional audit endpoint | ||||||||
| notemptyThese settings can only be applied to UTMs from version 12.6.2. | ||||||||
| Caption | Value | Description | ![]() | |||||
| URL | URL | Before a dry run is started and also after an update has been installed and started (but before the update is finalized), the appliance will test whether the Securepoint update server can be reached. Another endpoint (host name or IP address and port) can be specified here, the accessibility of which is also tested. A TCP handshake to a service on the specified server is checked. | ||||||
| Port | 443 | |||||||
Cyber Defense Cloud Cyber Defense Cloud | ||||||||
| notemptyThese settings can only be applied to UTMs from version 14.0 - Luna. | ||||||||
| Caption | Value | Description | ![]() | |||||
| Threat Intelligence Filter | Allows the configuration of the Threat Intelligence filter settings when activated | |||||||
| Log connection | When activated the connection is logged in the Syslog but allowed | |||||||
| Log and block connections | When activated , the connection is logged in the Syslog and blocked | |||||||
Data protection Data protection | ||||||||
| notemptyThese settings can only be applied to UTMs from version 14.0 - Luna. | ||||||||
| Caption | Value | Description | ![]() | |||||
| Manage data protection | Allows configuration of the data protection settings when activated | |||||||
| Enable for all Applications | Activates log anonymization for all applications on the UTM
| |||||||
Applications | ||||||||
| Application name | Log annonymization can be enabled individually for each application. Possible applications:
| |||||||
Fail2Ban Fail2Ban | ||||||||
| notemptyThese settings can only be applied to UTMs from version 14.0 - Luna. | ||||||||
| Caption | Value | Description | ![]() | |||||
| Manage Fail2Ban Settings | Allows configuration of the Fail2Ban settings when activated . Fail2Ban protection means that IP addresses are temporarily blocked in a certain number of failed login attempts is exceeded. The number can be configured on the UTM under | |||||||
| SMTP | When activated protection against brute-force attacks is enabled for the SMTP service | |||||||
| SSH | When activated protection against brute-force attacks is eneabled for the SSH service | |||||||
| Admin-Interface | When activated protection against brute-force attacks is enabled for the administration web interface | |||||||
| User-Interface | When activated protection against bruce-force attacks is enabled for the user web interface | |||||||
Cloud ShieldCloud Shield | ||||||||
| notemptyNew as of: 2.8.6 notemptyThe Securepoint Cloud Shield ensures that access to potentially dangerous or unwanted websites is blocked.
|
![]() | |||||||
| notemptyThese settings can only be applied to UTMs from version 14.1. | ||||||||
| notemptyAttention: If Cloud Shield is activated on the UTM, all DNS and DoT forwarders configured directly on the UTM are ignored. | ||||||||
| Caption | Value | Description | ||||||
| Activate Cloud Shield | If Cloud Shield is activated , a Cloud Shield profile can assigned and the logging of device names can be decided.
| |||||||
| Profiles | Select profile | The Cloud Shield profile to be used for the Cloud Shield configuration.
| ||||||
| Name | select attribute | Select which attribute should be used as the device name to identify the devices in the Cloud Shield statistics and logs. | ||||||
| Anonymous | Do not set a device name.
This means that the device cannot be identified in the statistics and logs. | |||||||
| Device Hostname | Use the hostname as the device name | |||||||
| Device Alias | Use the device alias as the device name | |||||||
| Device ID | Use the device id as the device name | |||||||
| Allow fallback DNS | Default |
| ||||||
Displayed for existing profiles | ||||||||
Cloud Scheduler Log Cloud Scheduler Log | ||||||||
|
![]() | |||||||
Publish-StatePublish-State
| ||||||||
| Log on the status of the publication of the profile on the assigned UTMs. | ||||||||
| Caption | Value | Description | ![]() | |||||
| Time | Shows the date and time at which the profile is published | |||||||
| Type | Indicates the type that is being executed | |||||||
| UTM | Displays the UTM where the profile is applied | |||||||
| Direction | Indicates the direction of communication
| |||||||
| Status | Displays the status of the executed job
| |||||||
| Save | Saves the information and closes the dialog | |||||||
| Close | Closes the dialog without saving the information | |||||||





















