McAfee HISCDE-AB-IA Product Guide - Page 72

FAQ — Use of wildcards in Firewall Rules, Create Firewall Rule

Page 72 highlights

Configuring Firewall Policies Define firewall protection 3 Determine how you want to view the list of client rules: To... Select columns to display Sort by a column Filter for groups Filter for creation time Filter for searched text Aggregate rules Do this... Select Choose Columns from the Options menu. In the Select Columns page, add, remove, or reorder the columns for the display. Click the column header. From the Filter menu select This Group Only or This Group and All Subgroups. Select the time the rule was created: None, Since, or Between. When selecting Since, enter a beginning date; when selecting Between, enter both a beginning and ending date. Click Clear to remove filter settings. Type the process path, process name, user name, computer name, or signature ID to filter on. Click Clear to remove filter settings. Click Aggregate, select the criteria on which to aggregate rules., then click OK. Click Clear to remove aggregation settings. 4 To move rules to a policy, select one or more in the list, click Create Firewall Rule, then indicate the policy to which to move the rules. FAQ - Use of wildcards in Firewall Rules When entering values in certain fields in firewall rules, Host IPS permits the use of wildcards. Which wildcards can I use for path and address values? For paths of files, registry keys, executables, and URLs, use these wildcards: Character ? (question mark) * (one asterisk) ** (two asterisks) | (pipe) Definition A single character. Multiple characters, excluding / and \. Use to match the root-level contents of a folder with no subfolders. Multiple characters, including / and \ . Wildcard escape. NOTE: For ** the escape is |*|*. NOTE: Registry key paths for firewall group locations do not recognize wildcard values. Which wildcards can I use for all other values? For values that normally do not contain path information with slashes, use these wildcards: Character ? (question mark) * (one asterisk) | (pipe) Definition A single character. Multiple characters, including / and \ . Wildcard escape. 72 McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

3
Determine how you want to view the list of client rules:
Do this...
To...
Select
Choose Columns
from the Options menu. In
the Select Columns page, add, remove, or reorder the
columns for the display.
Select columns to display
Click the column header.
Sort by a column
From the Filter menu select
This Group Only
or
This
Group and All Subgroups
.
Filter for groups
Select the time the rule was created: None, Since, or
Between. When selecting Since, enter a beginning date;
Filter for creation time
when selecting Between, enter both a beginning and
ending date. Click
Clear
to remove filter settings.
Type the process path, process name, user name,
computer name, or signature ID to filter on. Click
Clear
to remove filter settings.
Filter for searched text
Click
Aggregate
, select the criteria on which to
aggregate rules., then click
OK
. Click
Clear
to remove
aggregation settings.
Aggregate rules
4
To move rules to a policy, select one or more in the list, click
Create Firewall Rule
, then
indicate the policy to which to move the rules.
FAQ — Use of wildcards in Firewall Rules
When entering values in certain fields in firewall rules, Host IPS permits the use of wildcards.
Which wildcards can I use for path and address values?
For paths of files, registry keys, executables, and URLs, use these wildcards:
Definition
Character
A single character.
? (question mark)
Multiple characters, excluding / and \. Use to match the
root-level contents of a folder with no subfolders.
* (one asterisk)
Multiple characters, including / and \ .
** (two asterisks)
Wildcard escape.
NOTE:
For ** the escape is |*|*.
| (pipe)
NOTE:
Registry key paths for firewall group locations do not recognize wildcard values.
Which wildcards can I use for all other values?
For values that normally do not contain path information with slashes, use these wildcards:
Definition
Character
A single character.
? (question mark)
Multiple characters, including / and \ .
* (one asterisk)
Wildcard escape.
| (pipe)
Configuring Firewall Policies
Define firewall protection
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
72