McAfee HISCDE-AB-IA Product Guide - Page 34

Configuring the IPS Options policy, Network IPS enabled

Page 34 highlights

Configuring IPS Policies Enable IPS protection • Adaptive mode enabled (rules are learned automatically) - Select to enable adaptive mode, where clients create exception rules automatically to allow blocked behavior. Use only temporarily while tuning a deployment. NOTE: This control is also available directly on the client. • Retain existing client rules when this policy is enforced - Select to allow clients to keep exception rules created on the client, either automatically with adaptive mode or manually on a Windows client, when this policy is enforced. For Windows platforms only These options are available for clients on Windows platforms only: • Network IPS enabled - Select to enforce network IPS rules. This option is available independently from the application of host IPS rules. • Automatically block network intruders - Select this option to block incoming and outgoing traffic on a host until it is manually removed from a blocked list on the client for the number of minutes indicated. Available only if Network IPS is enabled. NOTE: These controls are also available directly on the client. • Retain blocked hosts - Select to allow a client to block a host IP address until the parameters set under "Automatically block network intruders." If not selected, the host is blocked only until the next policy enforcement. • Automatically include network-facing and service-based applications in the application protection list - Select to allow a client to add high-risk applications automatically to the list of protected applications in the IPS Rules policy. • Startup IPS protection enabled - Select to apply a hard-coded set of file and registry protection rules until the Host IPS service has started on the client. Policy selections This policy category contains a preconfigured policy, and an editable My Default policy, based on the McAfee Default policy. You can view and duplicate preconfigured policies; you can, create, edit, rename, duplicate, delete, and export custom policies. The preconfigured policy has these settings: McAfee Default Host IPS and Network IPS protection is disabled, and these options are are seleted to be applied when IPS protection is enabled: • Automatically block network intruders for 10 minutes (Windows only) • Retain blocked hosts (Windows only) • Retain client rules TIP: To activate IPS protection on client systems, the Host Intrusion Prevention administrator must first enable the Host IPS and Network IPS options in this policy, and then apply the policy to client systems. IPS protection on client systems is not automatic as in earlier versions of the product. Configuring the IPS Options policy Configure settings in this policy to turn IPS protection on and off or apply adaptive mode. 34 McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Adaptive mode enabled (rules are learned automatically)
— Select to enable adaptive
mode, where clients create exception rules automatically to allow blocked behavior. Use
only temporarily while tuning a deployment.
NOTE:
This control is also available directly on the client.
Retain existing client rules when this policy is enforced
— Select to allow clients to
keep exception rules created on the client, either automatically with adaptive mode or
manually on a Windows client, when this policy is enforced.
For Windows platforms only
These options are available for clients on Windows platforms only:
Network IPS enabled
— Select to enforce network IPS rules. This option is available
independently from the application of host IPS rules.
Automatically block network intruders
— Select this option to block incoming and
outgoing traffic on a host until it is manually removed from a blocked list on the client for
the number of minutes indicated. Available only if Network IPS is enabled.
NOTE:
These controls are also available directly on the client.
Retain blocked hosts
— Select to allow a client to block a host IP address until the
parameters set under "Automatically block network intruders." If not selected, the host is
blocked only until the next policy enforcement.
Automatically include network-facing and service-based applications in the
application protection list
— Select to allow a client to add high-risk applications
automatically to the list of protected applications in the IPS Rules policy.
Startup IPS protection enabled
— Select to apply a hard-coded set of file and registry
protection rules until the Host IPS service has started on the client.
Policy selections
This policy category contains a preconfigured policy, and an editable My Default policy, based
on the McAfee Default policy. You can view and duplicate preconfigured policies; you can,
create, edit, rename, duplicate, delete, and export custom policies.
The preconfigured policy has these settings:
McAfee Default
Host IPS and Network IPS protection is disabled, and these options are are seleted to be applied
when IPS protection is enabled:
Automatically block network intruders for 10 minutes (Windows only)
Retain blocked hosts (Windows only)
Retain client rules
TIP:
To activate IPS protection on client systems, the Host Intrusion Prevention administrator
must first enable the Host IPS and Network IPS options in this policy, and then apply the policy
to client systems. IPS protection on client systems is not automatic as in earlier versions of the
product.
Configuring the IPS Options policy
Configure settings in this policy to turn IPS protection on and off or apply adaptive mode.
Configuring IPS Policies
Enable IPS protection
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
34