McAfee HISCDE-AB-IA Product Guide - Page 139

Test Automatic Blocking of Network IPS, Network IPS Activity Log wProb

Page 139 highlights

Appendix B - Troubleshooting General issues 7 Do one of the following: • If the problem recurs, note whether the problem is associated with the IPS component but not the specific engines. Review hipshield.log to see if the IPS component is the problem. • If the problem does not recur, the issue might be associated with a specific engine. Continue to the next step, Test Each IPS Engine. Test each IPS engine 1 Click Help and select Troubleshooting. 2 Select Error reporting under IPS logging. 3 Select Log security violations. 4 Click Functionality. 5 Select the engines, one at a time, and retest. 6 Save a copy of the hipshield log for each test and label with the name of the engine tested, for reporting to support. 7 When testing is complete, enable all the engines to continue to the next step. Test IPS Adaptive Mode 1 Click the Activity Log tab and clear the log. 2 Click the IPS Policy tab and select Enable Adaptive Mode. 3 Test the system to determine if the problem recurs. 4 Do one of the following: • If the problem recurs, deselect Enable Adaptive Mode and retest to see if the problem is resolved. If it is, Host IPS in Adaptive Mode can potentially be associated with the issue. Save a copy of the Activity log and name it Host IPS Adaptive Activity Log wProb, for reporting to support. • If the problem does not recur, deselect Enable Host IPS and continue to the next step. Test Network IPS 1 Click the Activity Log tab and clear the log. 2 Click the IPS Policy tab and select Enable Network IPS. 3 Test the system to determine if the problem recurs. 4 Do one of the following: • If the problem recurs, deselect Enable Network IPS and retest to see if the problem is resolved. If it is, Network IPS can potentially be associated with the issue. Save a copy of the Activity log and name it Network IPS Activity Log wProb, for reporting to support. • If the problem does not recur, select Enable Network IPS and continue to the next step. Test Automatic Blocking of Network IPS 1 Click the Activity Log tab and clear the log. 2 Click the IPS Policy tab and select Enable Network IPS. 3 Click the Automatically Block Attackers checkbox. 4 Test the system to determine if the problem recurs. If it does: McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 139

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

7
Do one of the following:
If the problem recurs, note whether the problem is associated with the IPS component
but not the specific engines. Review hipshield.log to see if the IPS component is the
problem.
If the problem does not recur, the issue might be associated with a specific engine.
Continue to the next step,
Test Each IPS Engine
.
Test each IPS engine
1
Click
Help
and select
Troubleshooting
.
2
Select
Error
reporting under IPS logging.
3
Select
Log security violations
.
4
Click
Functionality
.
5
Select the engines, one at a time, and retest.
6
Save a copy of the hipshield log for each test and label with the name of the engine tested,
for reporting to support.
7
When testing is complete, enable all the engines to continue to the next step.
Test IPS Adaptive Mode
1
Click the
Activity Log
tab and clear the log.
2
Click the
IPS Policy
tab and select
Enable Adaptive Mode
.
3
Test the system to determine if the problem recurs.
4
Do one of the following:
If the problem recurs, deselect
Enable Adaptive Mode
and retest to see if the problem
is resolved. If it is, Host IPS in Adaptive Mode can potentially be associated with the
issue. Save a copy of the
Activity log
and name it
Host IPS Adaptive Activity Log
wProb
, for reporting to support.
If the problem does not recur, deselect
Enable Host IPS
and continue to the next
step.
Test Network IPS
1
Click the
Activity Log
tab and clear the log.
2
Click the
IPS Policy
tab and select
Enable Network IPS
.
3
Test the system to determine if the problem recurs.
4
Do one of the following:
If the problem recurs, deselect
Enable Network IPS
and retest to see if the problem
is resolved. If it is, Network IPS can potentially be associated with the issue. Save a
copy of the
Activity log
and name it
Network IPS Activity Log wProb
, for reporting
to support.
If the problem does not recur, select
Enable Network IPS
and continue to the next
step.
Test Automatic Blocking of Network IPS
1
Click the
Activity Log
tab and clear the log.
2
Click the
IPS Policy
tab and select
Enable Network IPS
.
3
Click the
Automatically Block Attackers
checkbox.
4
Test the system to determine if the problem recurs. If it does:
Appendix B — Troubleshooting
General issues
139
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5