The Assets monitoring panel is similar to the Blocks panel, but provides an asset-centric view of outbound activity originating from your network, displaying which addresses on your network have been blocked, grouped by Shunlist.
An IP address may show up multiple times in the Asset panel, once for each Shunlist with blocks. Clicking on an IP address will display more details about all blocked outbound traffic originating from that address.
Clicking on the IP address of a blocked aggressor will transition the view to display all assets on your network that have been blocked while attempting to contact that address. The Outbound Blocks per Asset element on the Blocks Summary modal dialog box will also appear for any outbound shun selected from the Blocks panel. This information can also be seen for any outbound blocks in the Top Ten summary, or via the Threat Intel Search feature.
With the Assets panel, IntelliShun is now capable of reporting on internal private IP addresses for outbound blocks, so long as the IntelliShun is placed on the LAN (Internal) side of the perimeter firewall or router. See the IntelliShun1G Network Placement Guide for details.
Assets are IP addresses on your network, belonging to workstations, servers, printers, phones or devices using your Wi-Fi. External assets have public, routable IP addresses -- your firewall, or servers that are accessible via the Internet. Internal assets are devices on your LAN with private IP addresses.
Aggressors are IP addresses that have been blocked for security or policy reasons.
Internet services generally operate on specific ports. Web servers use port 80 and 443, for example. The number of ports observed with outbound blocks is an indicator of the diversity of services that assets are attempting to contact via a given Shunlist.