McAfee HISCDE-AB-IA Product Guide - Page 75

Setting Client UI general options, Setting Client UI advanced options and passwords, General Settings

Page 75 highlights

Configuring General Policies Define client functionality 4 Click Save to save any changes. Setting Client UI general options Configure settings on the General Settings tab of the Client UI policy to determine icon display and intrusion event reactions for Windows clients only. On this tab you set the Client UI display options and indicate how the client responds upon an intrusion event. Task For option definitions, click ? in the interface. 1 Click the General Settings tab of the Client UI policy and under Display options select the option to display the tray icon for menu access to the client console or display the application in the Add/Remove Programs list. NOTE: Users who need to temporarily turn off a Host Intrusion Prevention feature to access a legitimate but blocked application or network site, they can use the Host Intrusion Prevention tray icon menu to disable a feature without opening the client console. The disabled feature remains disabled until restored by the menu command or the next policy enforcement. Note the following: • Disabling IPS disables both host IPS and network IPS protection. • If the Client UI is unlocked, the menu commands have no effect. For this feature, select to display the icon, then on the Advanced Options tab, select Allow disabling of features from the tray icon and select any or all of the features to be disabled. 2 Under Upon intrusion event, select the options that control how the client reacts when it encounters an intrusion. Setting Client UI advanced options and passwords Configure settings on the Advance Options tab of the Client UI policy for password access on Windows and non-Windows clients. Passwords unlock the Windows client console and access troubleshooting control on Windows and non-Windows clients. When this policy is applied to the client, the password is activated. Two types of passwords are available: • An administrator password, which an administrator can configure and is valid as long as the policy is applied to the client. The client console remains unlocked until it is closed. To reopen the client console controls, retype the administrator password. • A time-based password, which has an expiration date and time. This password is automatically generated. You can indicate the single system on which to create the password or create the password in the Client UI policy for all systems to which the policy is applied. The client console remains unlocked until it is closed. NOTE: Policies are not enforced on the client when the client console is unlocked. For details, see Unlocking the Windows client interface. McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 75

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

4
Click
Save
to save any changes.
Setting Client UI general options
Configure settings on the General Settings tab of the Client UI policy to determine icon display
and intrusion event reactions for Windows clients only.
On this tab you set the Client UI display options and indicate how the client responds upon an
intrusion event.
Task
For option definitions, click
?
in the interface.
1
Click the
General Settings
tab of the Client UI policy and under
Display options
select
the option to display the tray icon for menu access to the client console or display the
application in the Add/Remove Programs list.
NOTE:
Users who need to temporarily turn off a Host Intrusion Prevention feature to access
a legitimate but blocked application or network site, they can use the Host Intrusion
Prevention tray icon menu to disable a feature without opening the client console. The
disabled feature remains disabled until restored by the menu command or the next policy
enforcement. Note the following:
Disabling IPS disables both host IPS and network IPS protection.
If the Client UI is unlocked, the menu commands have no effect.
For this feature, select to display the icon, then on the
Advanced Options
tab, select
Allow disabling of features from the tray icon
and select any or all of the features to
be disabled.
2
Under
Upon intrusion event
, select the options that control how the client reacts when
it encounters an intrusion.
Setting Client UI advanced options and passwords
Configure settings on the Advance Options tab of the Client UI policy for password access on
Windows and non-Windows clients.
Passwords unlock the Windows client console and access troubleshooting control on Windows
and non-Windows clients. When this policy is applied to the client, the password is activated.
Two types of passwords are available:
An administrator password, which an administrator can configure and is valid as long as the
policy is applied to the client. The client console remains unlocked until it is closed. To reopen
the client console controls, retype the administrator password.
A time-based password, which has an expiration date and time. This password is automatically
generated. You can indicate the single system on which to create the password or create
the password in the Client UI policy for all systems to which the policy is applied. The client
console remains unlocked until it is closed.
NOTE:
Policies are
not
enforced on the client when the client console is unlocked.
For details, see
Unlocking the Windows client interface
.
Configuring General Policies
Define client functionality
75
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5