McAfee M-1250 IPS Configuration Guide - Page 44

Severity, Sensor Response, Enable Alert, Response > Logging, Notifications, Sensor Actions, Logging - review

Page 44 highlights

McAfee® Network Security Platform 5.1 Managing IPS settings 4 (Optional) Select the Severity for all selected attacks from the drop-down list. If there are multiple attacks with different severities, respectively, this action assigns the same severity across all selected attacks. 5 In the Sensor Response area, by default, the Enable Alert checkbox is empty. However, all attacks marked as "Enabled" in the "Configure Attack Detail for Attack Category: " table remain enabled. Note that the Response > Logging sub-tab as well as the Notifications area are unavailable for configuration: these areas become available once you select the Enable Alert check box. Do one of the following: Click the Enable Alert check box. Go to Step 6. Note: See Customizing responses for an exploit attack (on page 19) for all response parameter descriptions. Select Sensor responses (Sensor Actions). You can choose Sensor responses without checking Enable Alert. Go to the next step. 6 Click the Logging tab. 7 Select the Logging responses you want applied to all attacks. You must click both Enable Logging and Capture 128 Bytes check boxes to enable both logging responses. Figure 35: Logging Responses Selection 8 Go back to the Sensor Actions tab. 9 Select the check boxes next to the Sensor responses you want active for all attacks. 10 In the Notifications region, select the checkbox next to the notifications you want active for all attacks. Refer to Exploit attack notification (on page 21) for notification descriptions. 11 Click OK at the bottom of the window. A review page displays your customizations. 36

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259

McAfee® Network Security Platform 5.1
Managing IPS settings
36
4
(Optional) Select the
Severity
for all selected attacks from the drop-down list. If there
are multiple attacks with different severities, respectively, this action assigns the same
severity across all selected attacks.
5
In the
Sensor Response
area, by default, the
Enable Alert
checkbox is empty. However, all
attacks marked as “Enabled” in the “Configure Attack Detail for Attack Category:
<protocol
>” table remain enabled.
Note that the
Response > Logging
sub-tab as well as the
Notifications
area are unavailable
for configuration: these areas become available once you select the
Enable Alert
check
box.
Do one of the following:
±
Click the
Enable Alert
check box. Go to
Step
6
.
Note:
See Customizing responses for an exploit attack (on page
19
) for all
response parameter descriptions.
±
Select Sensor responses (
Sensor Actions
). You can choose Sensor responses
without checking
Enable Alert.
Go to the next step.
6
Click the
Logging
tab.
7
Select the
Logging
responses you want applied to all attacks. You must click both
Enable Logging
and
Capture 128 Bytes
check boxes to enable both logging responses.
Figure 35: Logging Responses Selection
8
Go back to the
Sensor Actions
tab.
9
Select the check boxes next to the Sensor responses you want active for all attacks.
10
In the
Notifications
region, select the checkbox next to the notifications you want active
for all attacks. Refer to Exploit attack notification (on page
21
) for notification
descriptions.
11
Click
OK
at the bottom of the window. A review page displays your customizations.