McAfee HISCDE-AB-IA Product Guide - Page 36

Configuring the IPS Protection policy, Define IPS protection

Page 36 highlights

Configuring IPS Policies Define IPS protection Name Maximum Protection Prepare for Enhanced Protection Prepare for Maximum Protection Warning Function Prevent high-, medium-, and low-severity signatures and log the rest. Prevent high-severity signatures, log medium-severity signatures, and ignore the rest. Prevent high- and medium-severity signatures, log low-severity signatures, and ignore the rest. Log high-severity signatures and ignore the rest. Configuring the IPS Protection policy Configure settings in this policy to set the protective reactions for signatures of a particular severity level. These settings instruct clients what to do when an attack or suspicious behavior is detected. Task For option definitions, click ? in the interface. 1 Click Menu | Policy | Policy Catalog and select Host Intrusion Prevention: IPS in the Product list and IPS Protection in the Category list. 2 In the IPS Protection policy list that appears, click Edit under Actions to change the settings for a custom policy. NOTE: For editable policies, other options include Rename, Duplicate, Delete, and Export. For non-editable policies, options include View and Duplicate. 3 In the IPS Protection page that appears, make any needed changes, then click Save. Define IPS protection The IPS Rules policy applies intrusion prevention safeguards. This policy is a multiple-instance policy that can have multiple instances assigned. Each IPS Rules policy contains configurable details on: • Signatures • Application Protection Rules • Exception Rules You also need to go to the Host IPS page under Reporting to work with: • IPS Events • IPS Client Rules Policy selections This policy category contains a preconfigured default policy, which provides basic IPS protection. You can view and duplicate the preconfigured policy; you can edit, rename, duplicate, delete, and export custom policies you create. You can also assign more than one instance of the policy for a union of various policy rules. 36 McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Function
Name
Prevent high-, medium-, and low-severity signatures and
log the rest.
Maximum Protection
Prevent high-severity signatures, log medium-severity
signatures, and ignore the rest.
Prepare for Enhanced Protection
Prevent high- and medium-severity signatures, log
low-severity signatures, and ignore the rest.
Prepare for Maximum Protection
Log high-severity signatures and ignore the rest.
Warning
Configuring the IPS Protection policy
Configure settings in this policy to set the protective reactions for signatures of a particular
severity level. These settings instruct clients what to do when an attack or suspicious behavior
is detected.
Task
For option definitions, click
?
in the interface.
1
Click
Menu | Policy | Policy Catalog
and select
Host Intrusion Prevention: IPS
in
the
Product
list and
IPS Protection
in the
Category
list.
2
In the
IPS Protection
policy list that appears, click
Edit
under
Actions
to change the
settings for a custom policy.
NOTE:
For editable policies, other options include Rename, Duplicate, Delete, and Export.
For non-editable policies, options include View and Duplicate.
3
In the
IPS Protection
page that appears, make any needed changes, then click
Save
.
Define IPS protection
The IPS Rules policy applies intrusion prevention safeguards. This policy is a multiple-instance
policy that can have multiple instances assigned.
Each IPS Rules policy contains configurable details on:
Signatures
Application Protection Rules
Exception Rules
You also need to go to the Host IPS page under Reporting to work with:
IPS Events
IPS Client Rules
Policy selections
This policy category contains a preconfigured default policy, which provides basic IPS protection.
You can view and duplicate the preconfigured policy; you can edit, rename, duplicate, delete,
and export custom policies you create. You can also assign more than one instance of the policy
for a union of various policy rules.
Configuring IPS Policies
Define IPS protection
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
36