Docs

Type at least 2 letters.

    Zone detail

    A Cloudflare zone's data in Advisor: monthly metrics, posture score, DNS records, rules and the ignore, recalculate and delete actions.

    Updated View as Markdown

    The zone detail shows the data Advisor collected for a Cloudflare zone: traffic, posture score, DNS records and rules. To open it, select the zone name on the Zones screen.

    The screen has three tabs: Métricas (Metrics), Registros DNS (DNS records) and Regras (Rules).

    Zone details

    The Detalhes da zona (Zone details) card sums up how the zone is identified. The info icon next to the title explains each field.

    Field What it shows
    Status The zone status in Cloudflare. See the statuses.
    Tipo (Type) The zone type in Cloudflare.
    ID na Cloudflare (Cloudflare ID) The zone identifier, with a copy button.
    Plano (Plan) The zone's Cloudflare plan.
    Plano legado (Legacy plan) The legacy plan reported by Cloudflare.
    Última sincronização (Last sync) When the zone was last collected.
    Domínio registrado (Registered domain) Shows when Cloudflare reports the domain registration.
    Vencimento do domínio (Domain expiration) Shows when Cloudflare reports the expiration date.
    Removida em (Removed on) Shows when the zone was removed from the Cloudflare account.

    When the zone has a score, the card also shows how it feeds the account score:

    Field What it shows
    Requisições (período) (Requests, period) The zone's requests in the period used for the calculation.
    Fatia do tráfego da conta (Share of account traffic) The part of the account traffic that went through this zone.
    Peso na nota da conta (Weight in account score) The zone's weight in the average, as X% · N× a média (X% · N× the average). With no metrics in the period it reads uniforme, sem métrica no período (uniform, no metrics in the period): every zone weighs the same.

    See how the account score is built.

    Zone information

    The Informações da zona (Zone information) button opens a side panel with the collected configuration, in groups:

    • TLS / HTTPS
    • HSTS
    • DNS (DNSSEC)
    • WAF gerenciado (Managed WAF)
    • Cabeçalhos de resposta (Response headers)
    • Proteções gerais (General protections)

    Metrics tab

    Monthly metrics

    The Métricas mensais (Monthly metrics) card shows one month's numbers. Pick the month in the selector. The window covers 24 months.

    Row What it measures
    Visitas (Visits) Visits to the zone.
    Banda total (Total bandwidth) Data transferred between the edge and visitors.
    Banda cacheada (Cached bandwidth) Data served straight from the edge cache.
    Req. cacheadas (Cached requests) Requests served from cache.
    Req. sem cache (Uncached requests) Requests sent to the origin server.
    Desafiadas (Challenged) Requests that received a WAF challenge.
    Erros 4xx (4xx errors) Responses with a 4xx error.
    Erros 5xx (5xx errors) Responses with a 5xx error.
    DDoS mitigado (DDoS mitigated) Requests mitigated by DDoS protection.

    Each row compares with the previous month (vs ant.) and the next one (vs seg.). Below, the Top bloqueados (Top blocked) section lists the zone's most blocked items in the month.

    Posture score

    The Score de postura (Posture score) panel, next to the metrics, shows the zone score and the evaluated recommendations. Each recommendation has one of these badges:

    Badge What it means
    Conforme (Compliant) The configuration meets the rule.
    Parcial (Partial) Partly meets the rule and earns part of the points.
    Não conforme (Non-compliant) Does not meet the rule. It is an open risk.
    Ignorada (Ignored) The risk was accepted and the rule left the score.
    N/A · requer Pro+, Business+ or Enterprise (requires plan) The rule needs a plan above the zone's plan.
    Não coletado (Not collected) The data did not come in the last collection.

    Not-applicable and compliant recommendations are collapsed under N não aplicáveis pelo plano (N not applicable for the plan) and N conformes (N compliant). Select a group to expand it.

    Recalculate

    Recalcular (Recalculate) rescans the zone in Cloudflare and recalculates the score without waiting for the scheduled collection. When it finishes, the message Zona reescaneada e score recalculado. (Zone rescanned and score recalculated.) appears.

    This action requires the posture.rules.write permission, which is not part of the default tenant roles. To enable it, contact Guardnet. See Roles and permissions.

    Ignore a recommendation

    Use Ignorar recomendação (Ignore recommendation) to accept the risk of a rule on this zone. The rule becomes Ignorada and leaves the score. To undo it, select Restaurar (Restore). Advisor confirms with the message Recomendação restaurada. Voltou a compor o score. (Recommendation restored. It counts toward the score again.)

    Penalty rules, which take points off the score, show Pontuação negativa: não pode ser ignorada (Negative score: cannot be ignored). They only leave the score once the configuration is fixed. See Risks and acceptance.

    Ignore zone

    Ignorar zona (Ignore zone) ignores, in a single action, every open recommendation of the zone that can be ignored.

    1. Select Ignorar zona.
    2. In the Ignorar todas as recomendações da zona (Ignore all zone recommendations) modal, fill in Justificativa (obrigatória, aplicada a todas) (Justification, required, applied to all).
    3. (Optional) To set an expiry for the acceptance, fill in Expira em (Expires on).
    4. Confirm.

    Ignoring a recommendation and ignoring the zone require the posture.ignores.write permission, included in the Tenant Admin role.

    DNS records tab

    The tab lists the zone's DNS records and shows how they count toward the score. Advisor probes each published record to learn whether it goes through the Cloudflare proxy and whether the origin accepts direct connections.

    Indicators

    Indicator What it shows
    Registros (Records) Total records and how many can be probed.
    Proxiados (Proxied) Records that go through the Cloudflare proxy.
    Origens expostas (Exposed origins) Origins that answer any IP.
    Origens restritas (Restricted origins) Origins that did not serve content directly.
    Pontos no score (Score points) Points earned over points possible, detailed as proxy x/y · origem x/y.

    Filters

    Filter Options
    Buscar nome ou conteúdo… (Search name or content…) Free text.
    Type Todos os tipos (All types) or one record type.
    Proxy Proxy: todos (all), Proxiado (Proxied), Direto (Direct), Proxiável sem proxy (Proxiable, not proxied).
    Published Publicado: todos (all), Ativo (Active), Inativo (Inactive), Indeterminado (Undetermined), Não se aplica (Not applicable).
    Origin Toda origem (All origins), Exposta (Exposed), Restrita (Restricted), Túnel (Tunnel), Indeterminado (Undetermined), Não se aplica (Not applicable).

    Columns

    Column What it shows
    Checkbox Selects records for bulk actions. Only shown with the posture.ignores.write permission.
    Nome (Name) The record name.
    Tipo (Type) The record type.
    Conteúdo (Content) The record content.
    Publicado (80/443) (Published) Whether the name answers on ports 80 and 443.
    Proxy Whether the record goes through the Cloudflare proxy.
    Origem (Origin) The origin status. See the table below.
    Pontos (Points) The record's points as +x/y. A * marks an active risk acceptance.

    The list is sorted by Origem, descending.

    What the origin means

    Origin What it means
    Exposta (Exposed) The origin answers any IP. Direct requests to the origin bypass the edge WAF and anti-DDoS protection.
    Restrita (Restricted) The origin did not serve content directly.
    Túnel (Tunnel) The record uses Cloudflare Tunnel; there is no reachable origin address.
    Indeterminado (Undetermined) No conclusion was possible. It counts neither for nor against.

    Record detail

    Expand a row to see the four probes: Publicado · HTTPS/HTTP (Published) and Origem · HTTPS/HTTP (Origin).

    The Pontuação no score da zona (Points in the zone score) section shows how many points the record earns (+N pontos). Each record's points are the rule's maximum points divided by the number of records it applies to.

    • Ignorar melhoria (Ignore improvement): accepts the risk for this record only, in this rule.
    • Restaurar (Restore): undoes the record's acceptance.
    • Restaurar regra (Restore rule): undoes the rule's acceptance.

    Bulk actions

    With records selected, use Ignorar recomendações de N registros marcados (Ignore recommendations for N selected records) or Restaurar aceites de … (Restore acceptances for …). Each action takes up to 500 records.

    Rules tab

    The tab lists the rules configured in Cloudflare for the zone, in the order Cloudflare evaluates them.

    • Indicators: Regras (Rules), Ativas (Active) and the Por ação (By action) strip.
    • Filters: Buscar nome ou expressão… (Search name or expression…), Todas as ações (All actions) and Status: todos (all) / Ativas (Active) / Desabilitadas (Disabled).
    • Columns: #, Nome (Name), Prévia (Preview), Ação (Action) and Status.

    Delete zone

    Excluir zona (Delete zone) removes from Advisor a zone that was already removed from Cloudflare. The button only shows for zones marked as removed and for users with the connections.zones.delete permission, included in the Tenant Admin role.

    1. Select Excluir zona.
    2. Read the warning in the Excluir zona do inventário (Delete zone from inventory) dialog: the zone and its whole history (metrics, security snapshots, DNS records, posture and risk acceptances) are deleted permanently.
    3. Confirm.