McAfee M-1250 IPS Configuration Guide - Page 46

Managing policies with Reconnaissance Policy Editor

Page 46 highlights

McAfee® Network Security Platform 5.1 Managing IPS settings 1 Select IPS Settings > Policies > IPS Policy Editor. 2 Select a policy. 3 Click Version Control. The IPS Policy Version List for Policy: dialog is displayed. The IPS Policy Version List displays the following information for each policy revision: Field Description Revision Indicates the revision number of the policy. When you edit a policy and save the changes, a new revision number is generated. For example, you have revision # 1, 2, and 3 of a policy. After reviewing, you modify revision #2 and save. The policy change is stored as revision #4. Version #0 indicates a policy created by McAfee or a policy upgraded from older versions of the Manager. Date The date when the revision was done. User The user who performed the policy revision. Description The name of the policy and the current revision number. Active Revision The check mark indicates the currently active version of the policy. You can perform the following actions: • Rollback: Allows you to revert to the selected revision of the policy. The selected version is then marked as the Active Revision. Note: This option is available only for policies that you can edit. • View: View details for the selected revision of the policy. You can also view the details under > Log > User Activity Audit. The audit log messages include the policy version number for all policy actions. • Delete: Delete any saved version of the policy. You can delete one or more revisions at the same time. Only un-applied policy revisions can be deleted. If you attempt to delete a current policy version, the Manager displays the message, "The selected revision cannot be deleted because it is currently the active revision." Note: This option is available only for policies that you can edit. • Show Diff: Compare any two revisions to view the differences. This option is enabled after you select two versions of the policy. Using Show Diff, you can opt for one of the following views: Snapshot: displays the differences at a high level that is, within logical groups Summary: displays details for all differences except attack details Detail: displays all data differences including attack details in the Exploit, Threshold, and Statistical sections. Managing policies with Reconnaissance Policy Editor The Reconnaissance Policy Editor action enables the use of the ultimate refining tool for Reconnaissance policy management. Using this editor, you can select the reconnaissance attacks you want to protect against, the types of automatic responses you need to block 38

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259

McAfee® Network Security Platform 5.1
Managing IPS settings
38
1
Select
IPS Settings > Policies > IPS Policy Editor
.
2
Select a policy.
3
Click
Version Control
.
The
IPS Policy Version List for Policy: <Policy Name>
dialog is displayed.
The
IPS Policy Version List
displays the following information for each policy revision:
Field
Description
Revision
Indicates the revision number of the policy. When you edit a
policy and save the changes, a new revision number is
generated. For example, you have revision # 1, 2, and 3 of a
policy. After reviewing, you modify revision #2 and save. The
policy change is stored as revision #4.
Version #0 indicates a policy created by McAfee or a policy
upgraded from older versions of the Manager.
Date
The date when the revision was done.
User
The user who performed the policy revision.
Description
The name of the policy and the current revision number.
Active
Revision
The check mark indicates the currently active version of the
policy.
You can perform the following actions:
Rollback
: Allows you to revert to the selected revision of the policy. The selected
version is then marked as the Active Revision.
Note
: This option is available only for policies that you can edit.
View
: View details for the selected revision of the policy.
You can also view the details under
<My Company>
> Log > User Activity Audit
. The audit
log messages include the policy version number for all policy actions.
Delete
: Delete any saved version of the policy. You can delete one or more revisions at
the same time.
Only un-applied policy revisions can be deleted. If you attempt to
delete a current policy version, the Manager displays the message, "The selected
revision cannot be deleted because it is currently the active revision."
Note
: This option is available only for policies that you can edit.
Show Diff
: Compare any two revisions to view the differences. This option is enabled
after you select two versions of the policy.
Using
Show Diff
, you can opt for one of the following views:
±
Snapshot
: displays the differences at a high level that is, within logical groups
±
Summary
: displays details for all differences except attack details
±
Detail
: displays all data differences including attack details in the Exploit,
Threshold, and Statistical sections.
Managing policies with Reconnaissance Policy Editor
The
Reconnaissance Policy Editor
action enables the use of the ultimate refining tool for
Reconnaissance policy management. Using this editor, you can select the reconnaissance
attacks you want to protect against, the types of automatic responses you need to block