McAfee HISCDE-AB-IA Product Guide - Page 71

Managing firewall client rules, Menu | Policy | Host IPS Catalog

Page 71 highlights

Configuring Firewall Policies Define firewall protection Task For option definitions, click ? in the interface. 1 Click Menu | Policy | Host IPS Catalog. 2 Under Item Type select a catalog item. Choices include: Group, Rule, Application, Process, Network, and Location. 3 Do any of the following on the catalog page: To... Filter for an item Change the view of items Edit an item Do this... Enter filter criteria, then click Set Filter. Click Clear to return to the default view. Select Options | Choose Columns, select, remove, or reorder columns, then click Save. Click the link associated with the item. Click Edit to edit the item, click Duplicate to create a copy of the item, click Delete to remove the item. NOTE: If you delete an item that has a dependent link, a new and independent copy of the deleted item is placed with the linking rule or group. Create and add an item Export a single item Export all items of the catalog type Import items of the catalog type Click New. In the page or pages that appear, enter the appropriate data, then click Save. Click the Export link associated with the item. Click Export in the upper-right corner of the page, then name and save the xml-format file. Click Import in the upper-right corner of the page, then locate and open the xml-format file with catalog data. NOTE: To add an item from the catalog while creating a firewall rule or group, click Add From Catalog at the bottom of the appropriate builder page. To add an item that you created while working in the firewall rule or group builder, click the Add to Catalog link next to the item. When you add an item from or to the catalog you create a dependent link between the item and the catalog with a Break Catalog Reference link. Clicking this link breaks the dependency between the item and the catalog and creates a new and independent item in its place with the linking rule or group. Managing firewall client rules Viewing firewall client rules created automatically in adaptive or learn mode or manually on a client and moving them to a Firewall Rules policy can tune and tighten security. NOTE: Access to Firewall Client Rules on the Host IPS tab under Reporting requires additional permissions other than that for Host Intrusion Prevention Firewall, including view permissions for Event Log, Systems, and System Tree access. Task For option definitions, click ? on the page displaying the options. 1 Click Menu | Reporting | Host IPS, then click Firewall Client Rules. 2 Select the group in the System Tree for which you want to display client rules. McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 71

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Task
For option definitions, click
?
in the interface.
1
Click
Menu | Policy | Host IPS Catalog
.
2
Under
Item Type
select a catalog item. Choices include:
Group
,
Rule
,
Application
,
Process
,
Network
, and
Location
.
3
Do any of the following on the catalog page:
Do this...
To...
Enter filter criteria, then click
Set Filter
. Click
Clear
to return to the default view.
Filter for an item
Select
Options | Choose Columns
, select, remove,
or reorder columns, then click
Save
.
Change the view of items
Click the link associated with the item. Click
Edit
to edit
the item, click
Duplicate
to create a copy of the item,
click
Delete
to remove the item.
NOTE:
If you delete an item that has a dependent link,
a new and independent copy of the deleted item is
placed with the linking rule or group.
Edit an item
Click
New
. In the page or pages that appear, enter the
appropriate data, then click
Save
.
Create and add an item
Click the
Export
link associated with the item.
Export a single item
Click
Export
in the upper-right corner of the page, then
name and save the xml-format file.
Export all items of the catalog type
Click
Import
in the upper-right corner of the page,
then locate and open the xml-format file with catalog
data.
Import items of the catalog type
NOTE:
To add an item from the catalog while creating a firewall rule or group, click
Add
From Catalog
at the bottom of the appropriate builder page. To add an item that you
created while working in the firewall rule or group builder, click the
Add to Catalog
link
next to the item. When you add an item from or to the catalog you create a dependent
link between the item and the catalog with a
Break Catalog Reference
link. Clicking this
link breaks the dependency between the item and the catalog and creates a new and
independent item in its place with the linking rule or group.
Managing firewall client rules
Viewing firewall client rules created automatically in adaptive or learn mode or manually on a
client and moving them to a Firewall Rules policy can tune and tighten security.
NOTE:
Access to Firewall Client Rules on the Host IPS tab under Reporting requires additional
permissions other than that for Host Intrusion Prevention Firewall, including view permissions
for Event Log, Systems, and System Tree access.
Task
For option definitions, click
?
on the page displaying the options.
1
Click
Menu | Reporting | Host IPS,
then click
Firewall Client Rules
.
2
Select the group in the System Tree for which you want to display client rules.
Configuring Firewall Policies
Define firewall protection
71
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5