McAfee HISCDE-AB-IA Product Guide - Page 65

Configuring the Firewall Options policy, Medium Risk

Page 65 highlights

Configuring Firewall Policies Enable firewall protection • Allow only outgoing traffic until the Host IPS service has started - Select to allow outgoing traffic but no incoming traffic until the Host IPS firewall service has started on the client. • Enable IP spoof protection - Select to block network traffic from non-local host IP addresses or from local processes that attempt to spoof their IP address. • Send events to ePO for TrustedSource violations - Select to send events to the ePO server if the TrustedSource block threshold setting for incoming or outgoing traffic is matched. • Incoming TrustedSource block threshold - Select from the list the TrustedSource rating at which to block incoming traffic from a network connection. Options include: High Risk, Medium Risk, Unverified, and Do not block. • Outgoing TrustedSource block threshold - Select from the list the TrustedSource rating at which to block outgoing traffic to a network connection. Options include: High Risk, Medium Risk, Unverified, and Do not block. Stateful firewall settings The stateful firewall settings are available: • FTP protocol inspection - A stateful firewall setting that allows FTP connections to be tracked so that they require only one firewall rule for outgoing FTP client traffic, and one for incoming FTP server traffic. If this option is not selected, FTP connections require an additional rule for incoming FTP client traffic and outgoing FTP server traffic. This should always be selected. • TCP connection timeout - The time in seconds a TCP connection that is not established remains active if no more packets matching the connection are sent or received. • UDP and ICMP echo virtual connection timeout - The time in seconds a UDP or ICMP echo virtual connection remains active if no more packets matching the connection are sent or received. It is reset to its configured value every time a packet that matches the virtual connection is sent or received. Policy selections This policy category contains one preconfigured policy and an editable My Default policy, based on the McAfee Default policy. You can view and duplicate preconfigured policies, and create, edit, rename, duplicate, delete, and export custom policies. The preconfigured policy has these settings: McAfee Default Firewall protection is disabled, and these options are selected to be applied when the firewall is enabled: • Allow bridged traffic • Retain client rules • Enable IP spoof protection • Use FTP protocol inspection Configuring the Firewall Options policy Configure settings in this policy to turn firewall protection on and off or apply adaptive or learn mode. McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 65

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Allow only outgoing traffic until the Host IPS service has started
— Select to allow
outgoing traffic but no incoming traffic until the Host IPS firewall service has started on the
client.
Enable IP spoof protection
— Select to block network traffic from non-local host IP
addresses or from local processes that attempt to spoof their IP address.
Send events to ePO for TrustedSource violations
— Select to send events to the ePO
server if the TrustedSource block threshold setting for incoming or outgoing traffic is matched.
Incoming TrustedSource block threshold
— Select from the list the TrustedSource
rating at which to block incoming traffic from a network connection. Options include:
High
Risk
,
Medium Risk
,
Unverified
, and
Do not block
.
Outgoing TrustedSource block threshold
— Select from the list the TrustedSource
rating at which to block outgoing traffic to a network connection. Options include:
High
Risk
,
Medium Risk
,
Unverified
, and
Do not block
.
Stateful firewall settings
The stateful firewall settings are available:
FTP protocol inspection
— A stateful firewall setting that allows FTP connections to be
tracked so that they require only one firewall rule for outgoing FTP client traffic, and one
for incoming FTP server traffic. If this option is not selected, FTP connections require an
additional rule for incoming FTP client traffic and outgoing FTP server traffic. This should
always be selected.
TCP connection timeout
— The time in seconds a TCP connection that is not established
remains active if no more packets matching the connection are sent or received.
UDP and ICMP echo virtual connection timeout
— The time in seconds a UDP or ICMP
echo virtual connection remains active if no more packets matching the connection are sent
or received. It is reset to its configured value every time a packet that matches the virtual
connection is sent or received.
Policy selections
This policy category contains one preconfigured policy and an editable My Default policy, based
on the McAfee Default policy. You can view and duplicate preconfigured policies, and create,
edit, rename, duplicate, delete, and export custom policies.
The preconfigured policy has these settings:
McAfee Default
Firewall protection is disabled, and these options are selected to be applied when the firewall
is enabled:
Allow bridged traffic
Retain client rules
Enable IP spoof protection
Use FTP protocol inspection
Configuring the Firewall Options policy
Configure settings in this policy to turn firewall protection on and off or apply adaptive or learn
mode.
Configuring Firewall Policies
Enable firewall protection
65
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5