McAfee HISCDE-AB-IA Product Guide - Page 16

Policy management, Where to find policies

Page 16 highlights

Managing Your Protection Policy management HIP Query Summary Firewall Errors Displays managed systems where the Firewall feature is enabled by policy but didn't start successfully. Firewall Status Displays where Firewall protection is enabled or disabled on managed systems. Host IPS Errors Displays managed systems where the IPS feature is enabled by policy but didn't start successfully. Host IPS Status Displays where IPS protection is enabled or disabled on managed systems. IPS Exceptions Report Displays IPS Rule policies that use IPS exceptions. Server High Triggered Signatures Displays the top 10 most triggered IPS signatures of High Severity (Critical). Server Medium Triggered Signatures Displays the top 10 most triggered IPS signatures of Medium Severity (Warning). Server Low Triggered Signatures Displays the top 10 most triggered IPS signatures of Low Severity (Notice). Service Status Displays where Host IPS is installed and whether it is running or not on managed systems. Top 10 IPS Events by Target Displays the top 10 systems with the most IPS events. Top 10 NIPS By Source IP Displays the top 10 network intrusion events by source IP addresses for the past three months. Top 10 Triggered Signatures Displays the top 10 triggered IPS signatures. Policy management Management of policies involves configuring and applying policies and the tuning of protection for system resources and applications. Part of this process requires an analysis of events and client rules. Where to find policies ePolicy Orchestrator provides two locations to view and manage Host Intrusion Prevention policies: the Assigned Policies tab (Systems | System Tree | Assigned Policies tab for a selected group in the System Tree) and the Policy Catalog tab (Systems | Policy Catalog). For a selected group or system, use the Assigned Policies tab to: • View the available policies of a particular feature of the product • View details of the policy • View inheritance information • Edit policy assignment • Edit custom policies Use the Policy Catalog to: • Create policies • View and edit policy information • View where a policy is assigned 16 McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Summary
HIP Query
Displays managed systems where the Firewall feature is enabled by policy but didn't
start successfully.
Firewall Errors
Displays where Firewall protection is enabled or disabled on managed systems.
Firewall Status
Displays managed systems where the IPS feature is enabled by policy but didn't start
successfully.
Host IPS Errors
Displays where IPS protection is enabled or disabled on managed systems.
Host IPS Status
Displays IPS Rule policies that use IPS exceptions.
IPS Exceptions Report
Displays the top 10 most triggered IPS signatures of High Severity (Critical).
Server High Triggered
Signatures
Displays the top 10 most triggered IPS signatures of Medium Severity (Warning).
Server Medium Triggered
Signatures
Displays the top 10 most triggered IPS signatures of Low Severity (Notice).
Server Low Triggered
Signatures
Displays where Host IPS is installed and whether it is running or not on managed
systems.
Service Status
Displays the top 10 systems with the most IPS events.
Top 10 IPS Events by Target
Displays the top 10 network intrusion events by source IP addresses for the past three
months.
Top 10 NIPS By Source IP
Displays the top 10 triggered IPS signatures.
Top 10 Triggered Signatures
Policy management
Management of policies involves configuring and applying policies and the tuning of protection
for system resources and applications. Part of this process requires an analysis of events and
client rules.
Where to find policies
ePolicy Orchestrator provides two locations to view and manage Host Intrusion Prevention
policies: the Assigned Policies tab (
Systems | System Tree | Assigned Policies
tab for a
selected group in the System Tree) and the Policy Catalog tab (
Systems | Policy Catalog
).
For a selected group or system, use the
Assigned Policies
tab to:
View the available policies of a particular feature of the product
View details of the policy
View inheritance information
Edit policy assignment
Edit custom policies
Use the
Policy Catalog
to:
Create policies
View and edit policy information
View where a policy is assigned
Managing Your Protection
Policy management
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
16