McAfee HISCDE-AB-IA Product Guide - Page 8

Host IPS policies

Page 8 highlights

Introducing Host Intrusion Prevention Host IPS policies • Basic network connectivity is allowed NOTE: When Host Intrusion Prevention 8.0 is first installed no protection is enabled. You must enable protection in the IPS Options or Firewall Options policy and apply the policy to the client. Advanced protection For advanced protection, switch from the default settings to stronger preset settings, or create custom settings. Start with a sample deployment to monitor and tune the new settings. Tuning involves balancing intrusion prevention protection and access to required information and applications per group type. Host IPS policies A policy is a collection of settings that you configure and enforce through the ePolicy Orchestrator console. Applying policies ensures that your security needs on managed systems are met. Host Intrusion Prevention provides three policy features, each with a set of security options. These are: IPS, Firewall, and General. IPS and firewall features contain a "rules" policy with rules that define behavior, and an "options" policy that enables or disables the rules. Ownership of policies is assigned in the Policy Catalog. After a policy is created, it can be edited or deleted only by the creator of the policy, the person associated as an owner of the policy, or the global administrator. Deleting a policy can be done only in the Policy Catalog. IPS policies The IPS feature contains three policies that protect both Windows and non-Windows computers. It details exceptions, signatures, application protection rules, events, and client-generated exceptions. • IPS Options (All platforms). Turns on or off IPS protection and application of adaptive mode for tuning. • IPS Protection (All platforms). Defines the protection reaction to events that signatures generate. • IPS Rules (All platforms). Defines signatures, exceptions, and application protection rules. This policy is a multiple instance policy, which allows for several IPS Rules policies, instead of a single policy, to be assigned to a system. The effective policy is then the result of the merged contents of the policies. If there are conflicting settings, the most protective explicit setting is applied. Firewall policies The Firewall feature contains three policies that protect Windows computers only. It filters network traffic, allowing legitimate traffic through the firewall and blocking the rest. • Firewall Options (Windows only). Turns on or off firewall protection and application of adaptive or learn mode for tuning. • Firewall Rules (Windows only). Defines firewall rules. • Firewall DNS Blocking (Windows only). Defines the domain name servers that are to be blocked. 8 McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Basic network connectivity is allowed
NOTE:
When Host Intrusion Prevention 8.0 is first installed no protection is enabled. You must
enable protection in the IPS Options or Firewall Options policy and apply the policy to the client.
Advanced protection
For advanced protection, switch from the default settings to stronger preset settings, or create
custom settings.
Start with a sample deployment to monitor and tune the new settings. Tuning involves balancing
intrusion prevention protection and access to required information and applications per group
type.
Host IPS policies
A policy is a collection of settings that you configure and enforce through the ePolicy Orchestrator
console. Applying policies ensures that your security needs on managed systems are met. Host
Intrusion Prevention provides three policy features, each with a set of security options. These
are:
IPS
,
Firewall
, and
General
. IPS and firewall features contain a “rules” policy with rules
that define behavior, and an “options” policy that enables or disables the rules.
Ownership of policies is assigned in the
Policy Catalog
. After a policy is created, it can be
edited or deleted only by the creator of the policy, the person associated as an owner of the
policy, or the global administrator. Deleting a policy can be done only in the
Policy Catalog
.
IPS policies
The IPS feature contains three policies that protect both Windows and non-Windows computers.
It details exceptions, signatures, application protection rules, events, and client-generated
exceptions.
IPS Options
(All platforms). Turns on or off IPS protection and application of adaptive
mode for tuning.
IPS Protection
(All platforms). Defines the protection reaction to events that signatures
generate.
IPS Rules
(All platforms). Defines signatures, exceptions, and application protection rules.
This policy is a multiple instance policy, which allows for several IPS Rules policies, instead
of a single policy, to be assigned to a system. The effective policy is then the result of the
merged contents of the policies. If there are conflicting settings, the most protective explicit
setting is applied.
Firewall policies
The Firewall feature contains three policies that protect Windows computers only. It filters
network traffic, allowing legitimate traffic through the firewall and blocking the rest.
Firewall Options
(Windows only). Turns on or off firewall protection and application of
adaptive or learn mode for tuning.
Firewall Rules
(Windows only). Defines firewall rules.
Firewall DNS Blocking
(Windows only). Defines the domain name servers that are to be
blocked.
Introducing Host Intrusion Prevention
Host IPS policies
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
8