McAfee HISCDE-AB-IA Product Guide - Page 87

Responding to Firewall alerts, Responding to Spoof Detected alerts, Allow

Page 87 highlights

Working with Host Intrusion Prevention Clients Overview of the Windows client Responding to Firewall alerts If you enable firewall protection and the learn mode for either incoming or outgoing traffic, a firewall alert appears, and the user needs to respond to it. The Application Information section displays information about the application attempting network access, including application name, path, and version. The Connection Information section displays information about the traffic protocol, address, and ports. NOTE: Previous and Next buttons are available in the Connection Information section if additional protocol or port information for an application is available. Previous and Next buttons are available at the bottom of the dialog box if more than one alert has been sent. Task 1 In the alert dialog box, do one of the following: • Click Deny to block this and all similar traffic. • Click Allow to permit this and all similar traffic through the firewall 2 Optional: Select options for the new firewall rule: Select... Create a firewall application rule for all ports and services To do this... Create a rule to allow or block an application's traffic over any port or service. If you do not select this option, the new firewall rule allows or blocks only specific ports: • If the intercepted traffic uses a port lower than 1024, the new rule allows or blocks only that specific port. • If the traffic uses port 1024 or higher, the new rule allows or blocks the range of ports from 1024 to 65535. Remove this rule when the application terminates Create a temporary allow or block rule that is deleted when the application is closed. If you do not select this options, the new firewall rule is created as a permanent client rule. Host Intrusion Prevention creates a new firewall rule based on the options selected, adds it to the Firewall Rules policy list, and automatically allows or blocks similar traffic. Responding to Spoof Detected alerts If you enable firewall protection, a spoof alert automatically appears if Host Intrusion Prevention detects an application on your computer sending out spoofed network traffic, and a user needs to respond to it. This means that the application is trying to make it seem like traffic from your computer actually comes from a different computer. It does this by changing the IP address in the outgoing packets. Spoofing is always suspicious activity. If you see this dialog box, immediately investigate the application that sent the spoofed traffic. NOTE: The Spoof Detected Alert dialog box appears only if you select the Display pop-up alert option. If you do not select this option, Host Intrusion Prevention automatically blocks the spoofed traffic without notifying you. The Spoof Detected Alert dialog box is very similar to the firewall feature's Learn Mode alert. It displays information about the intercepted traffic in two areas - the Application Information section, and the Connection Information section. McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 87

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Responding to Firewall alerts
If you enable firewall protection and the learn mode for either incoming or outgoing traffic, a
firewall alert appears, and the user needs to respond to it.
The Application Information section displays information about the application attempting
network access, including application name, path, and version. The Connection Information
section displays information about the traffic protocol, address, and ports.
NOTE:
Previous and Next buttons are available in the Connection Information section if additional
protocol or port information for an application is available. Previous and Next buttons are
available at the bottom of the dialog box if more than one alert has been sent.
Task
1
In the alert dialog box, do one of the following:
Click
Deny
to block this and all similar traffic.
Click
Allow
to permit this and all similar traffic through the firewall
2
Optional: Select options for the new firewall rule:
To do this...
Select...
Create a rule to allow or block an application’s traffic
over any port or service. If you do not select this option,
the new firewall rule allows or blocks only specific ports:
Create a firewall application rule for all ports and
services
If the intercepted traffic uses a port lower than
1024, the new rule allows or blocks only that
specific port.
If the traffic uses port 1024 or higher, the new rule
allows or blocks the range of ports from 1024 to
65535.
Create a temporary allow or block rule that is deleted
when the application is closed. If you do not select this
Remove this rule when the application terminates
options, the new firewall rule is created as a permanent
client rule.
Host Intrusion Prevention creates a new firewall rule based on the options selected, adds
it to the Firewall Rules policy list, and automatically allows or blocks similar traffic.
Responding to Spoof Detected alerts
If you enable firewall protection, a spoof alert automatically appears if Host Intrusion Prevention
detects an application on your computer sending out spoofed network traffic, and a user needs
to respond to it.
This means that the application is trying to make it seem like traffic from your computer actually
comes from a different computer. It does this by changing the IP address in the outgoing
packets. Spoofing is always suspicious activity. If you see this dialog box, immediately investigate
the application that sent the spoofed traffic.
NOTE:
The Spoof Detected Alert dialog box appears only if you select the Display pop-up alert
option. If you do not select this option, Host Intrusion Prevention automatically blocks the
spoofed traffic without notifying you.
The Spoof Detected Alert dialog box is very similar to the firewall feature’s Learn Mode alert.
It displays information about the intercepted traffic in two areas — the Application Information
section, and the Connection Information section.
Working with Host Intrusion Prevention Clients
Overview of the Windows client
87
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5