McAfee M-1250 IPS Configuration Guide - Page 238

cannot, Interface-x > Scanning > Custom DoS Policy, Inherited DoS, Commit Changes

Page 238 highlights

McAfee® Network Security Platform 5.1 The IPS Sensor_Name node Note: DoS policy cannot be customized to the VLAN/CIDR IDs within an interface if you have already created sub-interfaces. For more information, on how to customize DoS policy for a sub-interface, see Customizing DoS policy for a sub-interface (on page 239). For DoS policy application examples, see Setting policy for interfaces and sub-interfaces (on page 213). Tip: For more information on DoS modes, see Denial of Service (DoS) modes (on page 222). For more information on rules on creating DoS profiles, see Denial of Service (DoS) customization (on page 224). Figure 224: Manage Custom DoS To customize DoS detection instances within an interface, do the following: 1 Select Interface-x > Scanning > Custom DoS Policy . Initially, the table lists only the interface. The (Inherited DoS) highlight indicates that the interface is currently protected by the DoS settings of your applied IPS policy. 2 Click Edit. 3 Open a policy and make changes. 4 Click Commit Changes. 5 Click Version Control to track or review changes made to the policy. Note that Version Control is disabled till you commit the changes. Figure 225: Customize DoS Policy 230

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259

McAfee® Network Security Platform 5.1
The IPS Sensor_Name node
230
Note:
DoS policy
cannot
be customized to the VLAN/CIDR IDs within an interface if
you have already created sub-interfaces. For more information, on how to customize
DoS policy for a sub-interface, see Customizing DoS policy for a sub-interface (on
page
239
). For DoS policy application examples, see Setting policy for interfaces
and sub-interfaces (on page
213
).
Tip:
For more information on DoS modes, see Denial of Service (DoS) modes (on
page
222
). For more information on rules on creating DoS profiles, see Denial of
Service (DoS) customization (on page
224
).
Figure 224: Manage Custom DoS
To customize DoS detection instances within an interface, do the following:
1
Select
Interface-x > Scanning > Custom DoS Policy
. Initially, the table lists only the interface.
The
(Inherited DoS)
highlight indicates that the interface is currently protected by the
DoS settings of your applied IPS policy.
2
Click
Edit
.
3
Open a policy and make changes.
4
Click
Commit Changes
.
5
Click
Version Control
to track or review changes made to the policy.
Note that
Version Control
is disabled till you commit the changes.
Figure 225: Customize DoS Policy