McAfee HISCDE-AB-IA Product Guide - Page 89

Creating and editing IPS Policy exception rules, About the Firewall Policy tab

Page 89 highlights

Working with Host Intrusion Prevention Clients Overview of the Windows client Creating and editing IPS Policy exception rules View, create, and edit IPS exception rules on the IPS Policy tab on the client. Task 1 In the IPS Policy tab, click Add to add a rule. 2 In the Exception Rule dialog box, type a description for the rule. 3 Select the application the rule applies to from the application list, or click Browse to locate the application. 4 Select Exception rule is Active to make the rule active. Exception applies to all signatures, which is not enabled and selected by default, applies the exception to all signatures. 5 Click OK. 6 For other edits, do one of the following: To... View the details of a rule or edit a rule Make a rule active/inactive Delete a rule Apply changes immediately Do this... Double-click a rule, or select a rule and click Properties. The Exception Rule dialog box appears displaying rule information that can be edited. Select or clear the Exception rule is Active checkbox in the Exception Rule dialog box. You can also select or clear the checkbox next to the rule icon in the list. Select a rule and click Remove. Click Apply. If you do not click this button after making changes, a dialog box appears asking you to save the changes. About the Firewall Policy tab Use the Firewall Policy tab to configure the Firewall feature, which allows or blocks network communication based on rules that you define. From this tab you can enable or disable functionality and configure client firewall rules. For details on firewall policies, see Configuring Firewall Policies. The firewall rules list displays rules and rule groups relevant to the client and provides summary and detailed information for each rule. Rules in italics cannot be edited. Table 17: Firewall Policy tab Item Description Checkbox Indicates whether the rule is enabled (checked) or disabled (unchecked). For rules not in italics, you can enable and disable the rule with the checkbox. Firewall group Displays the list of rules it contains. Click the plus box to display the rules; click the minus box to hide the rules. Timed group Indicates the group is a timed group. Location-aware group Indicates the group is a location-aware group. McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 89

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Creating and editing IPS Policy exception rules
View, create, and edit IPS exception rules on the IPS Policy tab on the client.
Task
1
In the
IPS Policy
tab, click
Add
to add a rule.
2
In the
Exception Rule
dialog box, type a description for the rule.
3
Select the application the rule applies to from the application list, or click
Browse
to locate
the application.
4
Select
Exception rule is Active
to make the rule active.
Exception applies to all
signatures
, which is not enabled and selected by default, applies the exception to all
signatures.
5
Click
OK
.
6
For other edits, do one of the following:
Do this...
To...
Double-click a rule, or select a rule and click
Properties
. The
Exception Rule
dialog box appears
displaying rule information that can be edited.
View the details of a rule or edit a rule
Select or clear the Exception rule is Active checkbox in
the
Exception Rule
dialog box. You can also select or
clear the checkbox next to the rule icon in the list.
Make a rule active/inactive
Select a rule and click
Remove
.
Delete a rule
Click
Apply
. If you do not click this button after making
changes, a dialog box appears asking you to save the
changes.
Apply changes immediately
About the Firewall Policy tab
Use the Firewall Policy tab to configure the Firewall feature, which allows or blocks network
communication based on rules that you define. From this tab you can enable or disable
functionality and configure client firewall rules. For details on firewall policies, see
Configuring
Firewall Policies
.
The firewall rules list displays rules and rule groups relevant to the client and provides summary
and detailed information for each rule. Rules in italics cannot be edited.
Table 17: Firewall Policy tab
Description
Item
Indicates whether the rule is enabled (checked) or disabled
(unchecked). For rules not in italics, you can enable and
disable the rule with the checkbox.
Checkbox
Displays the list of rules it contains. Click the plus box to
display the rules; click the minus box to hide the rules.
Firewall group
Indicates the group is a timed group.
Timed group
Indicates the group is a location-aware group.
Location-aware group
Working with Host Intrusion Prevention Clients
Overview of the Windows client
89
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5