McAfee HISCDE-AB-IA Product Guide - Page 91

About the Blocked Hosts tab, Finish

Page 91 highlights

Working with Host Intrusion Prevention Clients Overview of the Windows client For this page... Transport Applications Schedule Enter this information... The protocol and the local or remote addresses where this rule applies. You can define an individual address, a range of addresses, a list of specific addresses, or specify all addresses. The applications that this rule applies to, including the executable file name. The schedule, if any, for the rule. 4 Click Finish to save the new rule. 5 For other edits, do one of the following: To... Do this... View the details of a rule or Select a rule and click Properties. The firewall rule builder dialog box appears edit a rule displaying rule information. If the rule is not in italic, you can edit it. Make a rule active/inactive Select or clear the checkbox next to Enabled on the General page of the firewall rule. You can also select or clear the checkbox next to the rule in the list. Make a copy of an existing rule Select the rule, usually a default rule that cannot be edited, and click Duplicate. Delete a rule Select a rule and click Remove. Apply changes immediately Click Apply. If you do not click this button after making changes, a dialog box appears asking you to save the changes. About the Blocked Hosts tab Use the Blocked Hosts tab to monitor a list of blocked hosts (IP addresses) that is automatically created when Network IPS (NIPS) protection is enabled. If Create Client Rules is selected in the IPS Options policy in the ePolicy Orchestrator console, you can add to and edit the list of blocked hosts. The blocked hosts list shows all hosts currently blocked by Host Intrusion Prevention. Each line represents a single host. You can get more information on individual hosts by reading the information in each column. Table 18: Blocked Hosts tab Column What it shows Source The IP address that Host Intrusion Prevention is blocking. Blocked Reason An explanation of why Host Intrusion Prevention is blocking this address. If Host Intrusion Prevention added this address to the list because of an attempted attack on your system, this column describes the type of attack. If Host Intrusion Prevention added this address because one of its firewall rules used the Treat rule match as intrusion option, this column lists the name of the relevant firewall rule. If you added this address manually, this column lists only the IP address that you blocked. Time Time Remaining The time and date when you added this address to the blocked addresses list. How long Host Intrusion Prevention continues to block this address. If you specified an expiration time when you blocked the address, this column shows the number of minutes left until Host Intrusion Prevention removes the address from McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 91

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Enter this information...
For this page...
The protocol and the local or remote addresses where this rule applies. You
can define an individual address, a range of addresses, a list of specific
addresses, or specify all addresses.
Transport
The applications that this rule applies to, including the executable file name.
Applications
The schedule, if any, for the rule.
Schedule
4
Click
Finish
to save the new rule.
5
For other edits, do one of the following:
Do this...
To...
Select a rule and click
Properties
. The firewall rule builder dialog box appears
displaying rule information. If the rule is not in italic, you can edit it.
View the details of a rule or
edit a rule
Select or clear the checkbox next to Enabled on the
General
page of the firewall
rule. You can also select or clear the checkbox next to the rule in the list.
Make a rule active/inactive
Select the rule, usually a default rule that cannot be edited, and click
Duplicate
.
Make a copy of an existing rule
Select a rule and click
Remove
.
Delete a rule
Click
Apply
. If you do not click this button after making changes, a dialog box
appears asking you to save the changes.
Apply changes immediately
About the Blocked Hosts tab
Use the Blocked Hosts tab to monitor a list of blocked hosts (IP addresses) that is automatically
created when Network IPS (NIPS) protection is enabled. If Create Client Rules is selected in
the IPS Options policy in the ePolicy Orchestrator console, you can add to and edit the list of
blocked hosts.
The blocked hosts list shows all hosts currently blocked by Host Intrusion Prevention. Each line
represents a single host. You can get more information on individual hosts by reading the
information in each column.
Table 18: Blocked Hosts tab
What it shows
Column
The IP address that Host Intrusion Prevention is blocking.
Source
An explanation of why Host Intrusion Prevention is blocking
this address.
If Host Intrusion Prevention added this address to the
list because of an attempted attack on your system, this
Blocked Reason
column describes the type of attack. If Host Intrusion
Prevention added this address because one of its firewall
rules used the
Treat rule match as intrusion
option,
this column lists the name of the relevant firewall rule.
If you added this address manually, this column lists only
the IP address that you blocked.
The time and date when you added this address to the
blocked addresses list.
Time
How long Host Intrusion Prevention continues to block this
address.
If you specified an expiration time when you blocked the
address, this column shows the number of minutes left
Time Remaining
until Host Intrusion Prevention removes the address from
Working with Host Intrusion Prevention Clients
Overview of the Windows client
91
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5