McAfee M-1250 IPS Configuration Guide - Page 188

Configuring ACL rules in the IPS Sensor, Not Available, Show Column

Page 188 highlights

McAfee® Network Security Platform 5.1 The IPS Sensor_Name node The Source and Destination OS columns in the Alerts page displays OS information for TCP traffic. These columns display "Not Available" in the following cases: • When OS finger printing is not enabled under IPS settings node • For non-TCP traffic • In instances where the stack has been modified OS information when McAfee NAC is enabled, is displayed in the Host page of the Threat Analyzer. This information is displayed in the OS column, and is available only for managed hosts and guest clients. For other hosts, the OS information is displayed as Not Available. For more information on managed hosts and guest clients, see NAC Configuration Guide. You can right-click in the Host page and select Show Column to display the OS column. Figure 188: OS Information For Managed Hosts Configuring ACL rules in the IPS Sensor The ACL tab provides actions for configuring access control list (ACL) rules and enabling of IP spoofing detection. The available ACL tab actions are: • Assigning Access Control List (ACL) rules (on page 181): Assign ACL rules and groups to Sensor/port or interfaces. • Editing ACL Log settings (on page 186): Manage ACL logging, a tool to help see which packets are permitted/dropped based on your ACL rules. • Enabling IP Address spoofing detection (on page 188): Enable detection of IP spoofing attacks. 180

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259

McAfee® Network Security Platform 5.1
The IPS Sensor_Name node
180
The Source and Destination OS columns in the Alerts page displays OS information for
TCP traffic. These columns display "Not Available" in the following cases:
When OS finger printing is not enabled under IPS settings node
For non-TCP traffic
In instances where the stack has been modified
OS information when McAfee NAC is enabled, is displayed in the Host page of the Threat
Analyzer.
This information is displayed in the
OS
column, and is available only for managed hosts
and guest clients. For other hosts, the OS information is displayed as
Not Available
. For
more information on managed hosts and guest clients, see
NAC Configuration Guide
.
You can right-click in the Host page and select
Show Column
to display the
OS
column.
Figure 188: OS Information For Managed Hosts
Configuring ACL rules in the IPS Sensor
The
ACL
tab provides actions for configuring access control list (ACL) rules and enabling of
IP spoofing detection. The available ACL tab actions are:
Assigning Access Control List (ACL) rules (on page
181
): Assign ACL rules and
groups to Sensor/port or interfaces.
Editing ACL Log settings (on page
186
): Manage ACL logging, a tool to help see
which packets are permitted/dropped based on your ACL rules.
Enabling IP Address spoofing detection (on page
188
): Enable detection of IP
spoofing attacks.