Policy Enforcement Dashboard

Qwall sits in front of outbound and inbound TLS as a policy gateway. It inspects each connection, classifies the cryptographic posture of the negotiated handshake, and records an allow, block, or warn decision against the active rule set. Every result shown here is simulated for demonstration.

10
Decisions
Recorded this session
4
Allowed
ML-KEM hybrid confirmed
4
Blocked
Classical key exchange
2
Warned
Posture unresolved

Active Policy — Strict

Change profile →
protected_preferred allow rule 1 of 5
protected allow rule 2 of 5
classical_fallback block rule 3 of 5
classical block rule 4 of 5
unknown warn rule 5 of 5

Recent Decisions

Full decision log →
Host Port Classification Action Timestamp
payments.firstnationalbank.com 443 Classical block 2026-08-26T06:29:00Z
api.firstnationalbank.com 443 Protected Preferred allow 2026-08-26T06:22:00Z
auth.firstnationalbank.com 443 Classical block 2026-08-26T06:15:00Z
reports.firstnationalbank.com 443 Protected allow 2026-08-26T06:08:00Z
legacy-core.fnbank.internal 8443 Unknown warn 2026-08-26T06:01:00Z
swift-gateway.firstnationalbank.com 443 Classical Fallback block 2026-08-26T05:54:00Z
cdn.firstnationalbank.com 443 Protected allow 2026-08-26T05:47:00Z
atm-network.fnbank.internal 9443 Classical block 2026-08-26T05:40:00Z

Classification Tiers

Protected Preferred ML-KEM-1024 hybrid negotiated — X25519MLKEM1024
Protected ML-KEM-768 hybrid negotiated — X25519MLKEM768
Classical Fallback Classical group chosen despite a hybrid offer
Classical No hybrid group available — RSA or ECDSA only
Unknown Handshake did not complete or was not observable