McAfee HISCDE-AB-IA Product Guide - Page 64

Firewall client rules, Enable firewall protection - machines

Page 64 highlights

Configuring Firewall Policies Enable firewall protection 3 If new rules are permitted, a unidirectional static allow rule is created. If this is s a TCP packet, an entry is made in the state table. 4 If a new rule is not permitted, the packet is dropped. Firewall client rules A client in adaptive or learn mode creates firewall client rules to allow blocked activity. Rules can also be created manually on the client computer. You can track the client rules and view them in a filtered or aggregated view. Use these client rules to create new policies or add them to existing policies. Filtering and aggregating rules Applying filters generates a list of rules that satisfies all of the variables defined in the filter criteria. The result is a list of rules that includes all of the criteria. Aggregating rules generates a list of rules grouped by the value associated with each of the variables selected in the Select columns to aggregate dialog box. The result is a list of rules displayed in groups and sorted by the value associated with the selected variables. Enable firewall protection The Firewall Options policy enables firewall protection and provides TrustedSource™ and stateful firewall settings. General settings These general options are available: • Enabled: Select to make the firewall active, and then select the type of protection: • Regular (default) - Use this setting when not tuning a deployment. • Adaptive mode - Select to have rules created automatically to allow traffic. Use only temporarily while tuning a deployment. • Learn mode - Select to have rules created after input from the user to allow traffic. Select also to allow incoming or outgoing traffic or both. Use only temporarily while tuning a deployment. • Allow traffic for unsupported protocols - Select to allow all traffic that uses unsupported protocols. With this option disabled, all traffic using unsupported protocols is blocked. • Allow bridged traffic - Select to allow traffic with a local MAC address that is not the local system's MAC address but is one of the MAC addresses in the list of VMs that the firewall supports. Use this option to allow traffic through a bridged environment with virtual machines. • Retain existing client rules when this policy is enforced - Select to allow clients to keep rules created on the client, automatically with adaptive mode, through user interaction with learn mode, or manually on a client, when this policy is enforced. Protection settings These settings enable special firewall-specific protection: 64 McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

3
If new rules are permitted, a unidirectional static allow rule is created. If this is s a TCP
packet, an entry is made in the state table.
4
If a new rule is not permitted, the packet is dropped.
Firewall client rules
A client in adaptive or learn mode creates firewall client rules to allow blocked activity. Rules
can also be created manually on the client computer. You can track the client rules and view
them in a filtered or aggregated view. Use these client rules to create new policies or add them
to existing policies.
Filtering and aggregating rules
Applying filters generates a list of rules that satisfies all of the variables defined in the filter
criteria. The result is a list of rules that includes all of the criteria. Aggregating rules generates
a list of rules grouped by the value associated with each of the variables selected in the
Select
columns to aggregate
dialog box. The result is a list of rules displayed in groups and sorted
by the value associated with the selected variables.
Enable firewall protection
The Firewall Options policy enables firewall protection and provides TrustedSource
and stateful
firewall settings.
General settings
These general options are available:
Enabled
: Select to make the firewall active, and then select the type of protection:
Regular (default)
— Use this setting when not tuning a deployment.
Adaptive mode
— Select to have rules created automatically to allow traffic. Use only
temporarily while tuning a deployment.
Learn mode
— Select to have rules created after input from the user to allow traffic.
Select also to allow incoming or outgoing traffic or both. Use only temporarily while tuning
a deployment.
Allow traffic for unsupported protocols
— Select to allow all traffic that uses
unsupported protocols. With this option disabled, all traffic using unsupported protocols is
blocked.
Allow bridged traffic
— Select to allow traffic with a local MAC address that is not the
local system's MAC address but is one of the MAC addresses in the list of VMs that the firewall
supports. Use this option to allow traffic through a bridged environment with virtual machines.
Retain existing client rules when this policy is enforced
— Select to allow clients to
keep rules created on the client, automatically with adaptive mode, through user interaction
with learn mode, or manually on a client, when this policy is enforced.
Protection settings
These settings enable special firewall-specific protection:
Configuring Firewall Policies
Enable firewall protection
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
64