McAfee HISCDE-AB-IA Product Guide - Page 57

Media type = Wired, Connection isolation on the corporate network

Page 57 highlights

Configuring Firewall Policies Overview of Firewall policies processed are traffic matching allow rules above the group in the firewall rules list, and traffic matching the group criteria. All other traffic is blocked. NOTE: Any group with connection isolation enabled cannot have associated transport options or applications. Figure 2: Network connection isolation As examples of using the connection isolation option, consider two settings: a corporate environment and a hotel. The active firewall rules list contains rules and groups in this order: 1 Rules for basic connection 2 VPN connection rules 3 Group with corporate LAN connection rules 4 Group with VPN connection rules Connection isolation on the corporate network Connection rules are processed until the group with corporate LAN connection rules is encounterd. This group contains these settings: • Media type = Wired McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 57

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

processed are traffic matching allow rules above the group in the firewall rules list, and traffic
matching the group criteria. All other traffic is blocked.
NOTE:
Any group with connection isolation enabled cannot have associated transport options
or applications.
Figure 2: Network connection isolation
As examples of using the connection isolation option, consider two settings: a corporate
environment and a hotel. The active firewall rules list contains rules and groups in this order:
1
Rules for basic connection
2
VPN connection rules
3
Group with corporate LAN connection rules
4
Group with VPN connection rules
Connection isolation on the corporate network
Connection rules are processed until the group with corporate LAN connection rules is encounterd.
This group contains these settings:
Media type = Wired
Configuring Firewall Policies
Overview of Firewall policies
57
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5