# Firewall Audit and Quarantine Capability

**Using Nexus Repository 3.94.0+? Check out our updated workflow**

This page describes the Firewall capability configuration workflow used for Nexus Repository versions **before 3.94.0**. From Nexus Repository 3.94.0 forward, Firewall is configured at the repository level by using Firewall Modes.

For the current workflow, see [Firewall Configuration for Nexus Repository](https://help.sonatype.com/en/firewall-configuration-for-nexus-repository.html "Firewall Configuration for Nexus Repository").

The Repository Firewall configuration may be managed by setting the _Firewall Audit and Quarantine_ capability for each proxy repository that will need to be protected.

## Adding the Audit and Quarantine Capability

1. Log in to Nexus Repository Pro 3 with Administrator credentials.
2. Go to _Settings_ → _System_ → _Capabilities_.
3. Select _Create Capability_.
4. Under _Select Capability Type_, select _Firewall Audit and Quarantine_.

5. From the dropdown list, select the repository to configure with the Repository Firewall.
6. Select the _Enable Quarantine for Repository_ checkbox and click _Create Capability_ button.

The audit on the selected repository starts automatically. Nexus Repository connects to the IQ Server and evaluates the components within the selected repository against any associated policy.

The `Quarantine` option is required to protect your repository from critical threats. By default, only malicious components are quarantined; these should never be allowed in your repository. You have control over the Repository Firewall's enforcement using actions on your IQ Server policies.

See [Managing the Quarantine](https://help.sonatype.com/en/firewall-quarantine.html "Firewall Quarantine")

## Disabling the Audit and Quarantine Capability

Disabling quarantine will release all quarantined components to your proxy repository. Previously quarantined components are not quarantined again. Only new components are evaluated for quarantine when quarantine is re-enabled.

To disable Audit and Quarantine:

1. In Nexus Repository, navigate to the _Settings_ menu and select _Capabilities_ under _System_.
2. Select the _Firewall Audit and Quarantine_ capability for the target repository.
3. Select _Disable_. It disables the quarantine capability as well.
4. To disable only quarantine, go to the _Settings_ tab and deselect the _Enable Quarantine for Repository_ checkbox.

5. Select _Save_.
