McAfee HISCDE-AB-IA Product Guide - Page 37

Configuring the IPS Rules policy, Assigning multiple instances of the policy

Page 37 highlights

Configuring IPS Policies Define IPS protection Configuring the IPS Rules policy Configure settings in this policy to define signatures, applications protection rules, and exceptions. Task For option definitions, click ? in the interface. 1 Click Menu | Policy | Policy Catalog and select Host Intrusion Prevention: IPS in the Product list and IPS Rules in the Category list. The list of policies appears. 2 In the IPS Rules policy list, click Edit under Actions to change the settings for a custom policy. NOTE: For editable policies, other options include: Rename, Duplicate, Delete, and Export. For non-editable policies, options include View and Duplicate. 3 In the IPS Rulespage that appears, make any needed changes, then click Save. See Configuring IPS signatures, Configuring IPS application protection rules, and Configuring IPS exceptions for details. Assigning multiple instances of the policy Assigning one or more instances of the policy to a group or system in the ePolicy Orchestrator System Tree provides for single policy multi-purpose protection. The IPS Rules policy and the Trusted Applications policy are multiple-instance policies that can have more than one instance assigned. A multiple-instance policy can be useful for an IIS Server, for example, where you might apply a general default policy, a server policy, and an IIS policy, the latter two configured to specifically target systems running as IIS servers. When assigning multiple instances, you are assigning a union of all the elements in each instance of the policy. NOTE: The McAfee Default policy for both IPS Rules and Trusted Applications are updated when content is update. McAfee recommends that these two policies always be applied to make sure protection as up to date as possible. For the policies that have multiple instances, an Effective Policy link appears to provide a view of the details of the combined policy instances. Task For option definitions, click ? in the interface. 1 Click Menu | Systems | System Tree and select a group in the System Tree. NOTE: For a single system, select a group in the System Tree that contains the system, then on the Systems tab, select the system and select Actions | Agent | Modify Policies on a Single System. 2 Under Assigned Policies, select Host Intrusion Prevention 8.0 : IPS/General in the Product list, and for IPS Rules/Trusted Applications click Edit Assignments. 3 On the Policy Assignment page, click New Policy Instance, and select a policy from the Assigned Polices list for the additional policy instance. To view the effective or combined effect of multiple instance rule sets, click View Effective Policy. 4 Click Save to save all changes. McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 37

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Configuring the IPS Rules policy
Configure settings in this policy to define signatures, applications protection rules, and exceptions.
Task
For option definitions, click
?
in the interface.
1
Click
Menu | Policy | Policy Catalog
and select
Host Intrusion Prevention: IPS
in
the
Product
list and
IPS Rules
in the
Category
list. The list of policies appears.
2
In the
IPS Rules
policy list, click
Edit
under
Actions
to change the settings for a custom
policy.
NOTE:
For editable policies, other options include: Rename, Duplicate, Delete, and Export.
For non-editable policies, options include View and Duplicate.
3
In the
IPS Rules
page that appears, make any needed changes, then click
Save
. See
Configuring IPS signatures
,
Configuring IPS application protection rules
, and
Configuring
IPS exceptions
for details.
Assigning multiple instances of the policy
Assigning one or more instances of the policy to a group or system in the ePolicy Orchestrator
System Tree provides for single policy multi-purpose protection.
The IPS Rules policy and the Trusted Applications policy are multiple-instance policies that can
have more than one instance assigned. A multiple-instance policy can be useful for an IIS
Server, for example, where you might apply a general default policy, a server policy, and an
IIS policy, the latter two configured to specifically target systems running as IIS servers. When
assigning multiple instances, you are assigning a union of all the elements in each instance of
the policy.
NOTE:
The McAfee Default policy for both IPS Rules and Trusted Applications are updated when
content is update. McAfee recommends that these two policies always be applied to make sure
protection as up to date as possible.
For the policies that have multiple instances, an Effective Policy link appears to provide a view
of the details of the combined policy instances.
Task
For option definitions, click
?
in the interface.
1
Click
Menu | Systems | System Tree
and select a group in the System Tree.
NOTE:
For a single system, select a group in the System Tree that contains the system,
then on the
Systems
tab, select the system and select
Actions | Agent | Modify Policies
on a Single System
.
2
Under Assigned Policies, select
Host Intrusion Prevention 8.0 : IPS/General
in the
Product
list, and for
IPS Rules/Trusted Applications
click
Edit Assignments
.
3
On the
Policy Assignment
page, click
New Policy Instance
, and select a policy from
the
Assigned Polices
list for the additional policy instance. To view the effective or
combined effect of multiple instance rule sets, click
View Effective Policy
.
4
Click
Save
to save all changes.
Configuring IPS Policies
Define IPS protection
37
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5