McAfee M-1250 Deployment Guide - Page 35

Define DoS policies., Define user roles.

Page 35 highlights

McAfee® Network Security Platform 6.0 Deployment Scenarios  Split your deployment into multiple Admin Domains. You may want to organize your deployment by geographical location, business unit, or functional area (that is, HR, Finance).  Segment your network traffic into VLAN tags and CIDR blocks. You can then monitor various traffic with distinct policies using the sub-interfaces feature.  Create (or clone) policies on a sub-interface basis. Create policies tuned for specific traffic flows within a network segment, and apply them on an extremely granular level.  Define user roles. Delegate the day-to-day management of the IPS to specific individuals, providing each person with only enough access to the system to carry out his/her responsibilities.  Define DoS policies. Configure DoS policies for specific hosts or a subset of your network. 28

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36

McAfee® Network Security Platform 6.0
Deployment Scenarios
28
Split your deployment into multiple Admin Domains.
You may want to organize your
deployment by geographical location, business unit, or functional area (that is, HR,
Finance).
Segment your network traffic into VLAN tags and CIDR blocks.
You can then monitor various
traffic with distinct policies using the sub-interfaces feature.
Create (or clone) policies on a sub-interface basis.
Create policies tuned for specific traffic
flows within a network segment, and apply them on an extremely granular level.
Define user roles.
Delegate the day-to-day management of the IPS to specific individuals,
providing each person with only enough access to the system to carry out his/her
responsibilities.
Define DoS policies.
Configure DoS policies for specific hosts or a subset of your
network.