McAfee HISCDE-AB-IA Product Guide - Page 138

Host IPS Activity Log wProb, Enable Host IPS

Page 138 highlights

Appendix B - Troubleshooting General issues How do I isolate a component in Host IPS to find out which one is causing a problem? NOTE: This process includes steps that might require repeated restarts, logons, or recreating issues. The following steps should be performed on the local client system with the Host IPS console. If you find the cause of the issue but cannot resolve it, forward the logs you obtain to McAfee Support. Disable all components and test for failure: 1 Disable IPS: Click the IPS Policy tab, and deselect Enable Host IPS and Enable Network IPS. 2 Disable Firewall: Click the Firewall Policy tab, and deselect Enable Firewall. 3 Clear the Blocked Hosts list: Click the Blocked Hosts tab and clear the list by selecting each entry and clicking Remove. 4 Enable Activity logging: Click the Activity Log tab and verify that all traffic logging and filter option checkboxes are selected. 5 Test the system to see if the problem recurs: • If the problem persists, continue to Step 6, • If the problem stops, skip to Step 1 of the Iterative testing phase. 6 Check the following: • Stop the McAfee Host IPS service and retest. If the problem goes away, report the issue as associated directly with the service. • Uninstall the Host IPS client from the local system and retest. If the problem goes away, report the issue as associated with installed files and not a specific component. Iterative Testing phase of each component: Test Host IPS 1 Click the Activity Log tab and clear the log. 2 Click the IPS Policy tab and select Enable Host IPS. 3 Test the system to determine if the problem recurs: • If the problem does not recur, skip to Step 5, Test Network IPS. • If the problem recurs: 1 Deselect Enable Host IPS. 2 Retest to verify the problem goes away. If the problem is resolved, Host IPS can potentially be associated with the issue. 3 Save a copy of the Activity log and name it Host IPS Activity Log wProb, for reporting to support. 4 Select Enable Host IPS and verify that the problem returns. Test all IPS engines 1 Click Help and select Troubleshooting. 2 Select Error reporting under IPS logging. 3 Select Log security violations. 4 Click Functionality. 5 On the HIPS Engines dialog box, deselect Enable / Disable all engines and click OK. 6 Test the system to determine if the problem recurs. 138 McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

How do I isolate a component in Host IPS to find out which one is causing a problem?
NOTE:
This process includes steps that might require repeated restarts, logons, or recreating
issues. The following steps should be performed on the local client system with the Host IPS
console. If you find the cause of the issue but cannot resolve it, forward the logs you obtain to
McAfee Support.
Disable all components and test for failure:
1
Disable IPS: Click the
IPS Policy
tab, and deselect
Enable Host IPS
and
Enable Network
IPS
.
2
Disable Firewall: Click the
Firewall Policy
tab, and deselect
Enable Firewall
.
3
Clear the Blocked Hosts list: Click the Blocked Hosts tab and clear the list by selecting each
entry and clicking
Remove
.
4
Enable Activity logging: Click the
Activity Log
tab and verify that all traffic logging and
filter option checkboxes are selected.
5
Test the system to see if the problem recurs:
If the problem persists, continue to Step 6,
If the problem stops, skip to Step 1 of the
Iterative testing phase
.
6
Check the following:
Stop the McAfee Host IPS service and retest. If the problem goes away, report the issue
as associated directly with the service.
Uninstall the Host IPS client from the local system and retest. If the problem goes away,
report the issue as associated with installed files and not a specific component.
Iterative Testing phase of each component:
Test Host IPS
1
Click the
Activity Log
tab and clear the log.
2
Click the
IPS Policy
tab and select
Enable Host IPS
.
3
Test the system to determine if the problem recurs:
If the problem does not recur, skip to Step 5, Test Network IPS.
If the problem recurs:
1
Deselect
Enable Host IPS
.
2
Retest to verify the problem goes away. If the problem is resolved, Host IPS can
potentially be associated with the issue.
3
Save a copy of the Activity log and name it
Host IPS Activity Log wProb
, for
reporting to support.
4
Select
Enable Host IPS
and verify that the problem returns.
Test all IPS engines
1
Click
Help
and select
Troubleshooting
.
2
Select
Error
reporting under IPS logging.
3
Select
Log security violations
.
4
Click
Functionality
.
5
On the HIPS Engines dialog box, deselect
Enable / Disable all engines
and click
OK
.
6
Test the system to determine if the problem recurs.
Appendix B — Troubleshooting
General issues
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
138