Go to Configuration > Threat Intelligence, and click the ACTIONS tab.
Click New.
Fill out all of the required fields. In the TYPE field, select Send an email message.
To send the message to multiple recipients, enter their email addresses in the TO field, separated with a semi-colon(;).
Click Save to save your changes when finished.
Go to Configuration > Threat Intelligence > Policy > Default Policy Group and select New.
From the Policy Conditions section, choose your source.
Select the IP address of the critical server as asset for the destination policy condition.
In this example, we are using 172.16.0.1.
Click Add More Conditions, and select Reputation as a policy condition.
Change the Reputation Parameters values as follows:
Click Add New
You can now see both the Destination and Reputation in the upper part of the page.
Go to Configuration > Threat Intelligence > Policy.
Select the desired policy rule and click the Modify button.
Scroll down the page and expand the Policy Consequences section.
In the Actions section, select which action you want to assign from the Available Actions section on the right.
Add it by clicking the plus (+) sign, or by dragging it to the Active Actions section.
Click the Update Policy button to save your changes and exit the policy modify page.
Click the Reload Policies button on the main policies page to refresh and display the changes.
Move the policy to a desired position on the list. See Policy Order and Grouping for details.