McAfee HISCDE-AB-IA Product Guide - Page 56

Firewall rule group connection isolation, Location status, Local Network, DNS Suffix, Default Gateway

Page 56 highlights

Configuring Firewall Policies Overview of Firewall policies • Registry key On the Network Options tab: • Local IP address • Media type If two location-aware groups apply to a connection, Host Intrusion Prevention uses normal precedence and processes the first applicable group in its rule list. If no rule in the first group matches, rule processing continues and might match a rule in the next group. When Host Intrusion Prevention matches a location-aware group's parameters to an active connection, it applies the rules within the group. It treats the rules as a small rule set and uses normal precedence. If some rules do not match the intercepted traffic, the firewall ignores them. Note the following: • If Location status is selected, a location name is required. • If Local Network is selected, the IP address of the adapter must match one of the list entries. • If DNS Suffix is selected, the DNS suffix of the adapter must match one of the list entries. • If Default Gateway is selected, the default adapter Gateway IP must match at least one of the list entries. • If DHCP Server is selected, the adapter DHCP server IP must match at least one of the list entries. • If DNS Server List is selected, the adapter DNS server IP address must match any of the list entries. • If Primary WINS Server is selected, the adapter primary WINS server IP address must match at least one of the list entries. • If Secondary WINS Server is selected, the adapter secondary WINS server IP address must match at least one of the list entries. Firewall rule group connection isolation A connection isolation option is available for groups to prevent undesirable traffic from accessing a designated network. This can be done through other active network interfaces on a computer, such as a wireless adapter connecting to a wi-fi hotspot while a wired adapter is connected to a LAN. When the Isolate this connection option is selected under a group's Location settings, and an active Network Interface Card (NIC) matches the group criteria, the only types of traffic 56 McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Registry key
On the Network Options tab:
Local IP address
Media type
If two location-aware groups apply to a connection, Host Intrusion Prevention uses normal
precedence and processes the first applicable group in its rule list. If no rule in the first group
matches, rule processing continues and might match a rule in the next group.
When Host Intrusion Prevention matches a location-aware group’s parameters to an active
connection, it applies the rules within the group. It treats the rules as a small rule set and uses
normal precedence. If some rules do not match the intercepted traffic, the firewall ignores
them.
Note the following:
If
Location status
is selected, a location name is required.
If
Local Network
is selected, the IP address of the adapter must match one of the list
entries.
If
DNS Suffix
is selected, the DNS suffix of the adapter must match one of the list entries.
If
Default Gateway
is selected, the default adapter Gateway IP must match at least one
of the list entries.
If
DHCP Server
is selected, the adapter DHCP server IP must match at least one of the list
entries.
If
DNS Server List
is selected, the adapter DNS server IP address must match any of the
list entries.
If
Primary WINS Server
is selected, the adapter primary WINS server IP address must
match at least one of the list entries.
If
Secondary WINS Server
is selected, the adapter secondary WINS server IP address
must match at least one of the list entries.
Firewall rule group connection isolation
A connection isolation option is available for groups to prevent undesirable traffic from accessing
a designated network. This can be done through other active network interfaces on a computer,
such as a wireless adapter connecting to a wi-fi hotspot while a wired adapter is connected to
a LAN.
When the
Isolate this connection
option is selected under a group's Location settings, and
an active Network Interface Card (NIC) matches the group criteria, the only types of traffic
Configuring Firewall Policies
Overview of Firewall policies
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
56