Symantec 10521148 Implementation Guide - Page 132

About response rules

Page 132 highlights

124 Configuring detection and response About response rules 2 Click Delete. Note: You must unapply policies before deleting them. If you do not, the interfaces will contain applied policies without definitions. About response rules Response rules are available on both the appliance and the software version of Symantec Network Security, with no differences. Response rules provide a way to automate responses for configurable sets of event types, source and target addresses, and severity. You can apply multiple response rules for the same event type when using either in-line mode or passive mode on the 7100 Series. Response rules have no effect on sensor behavior. Configurable responses include: ■ Console notification ■ Email or pager notification ■ SNMP trap ■ Traffic recording ■ TCP reset ■ TrackBack ■ Custom actions on the console or node Some response actions, such as email or SNMP, can be tuned by configuring related Network Security parameters. This section provides procedures for: ■ Adding response rules ■ Deleting response rules For a full description of all aspects of response rules, see the Symantec Network Security Administration Guide. Adding response rules This section provides the basic procedure for adding a response rule in the Network Security console. For more information about the available choices in each step, see the Symantec Network Security Administration Guide.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214

124
Configuring detection and response
About response rules
2
Click
Delete
.
Note:
You must unapply policies before deleting them. If you do not, the
interfaces will contain applied policies without definitions.
About response rules
Response rules are available on both the appliance and the software version of
Symantec Network Security, with no differences. Response rules provide a way
to automate responses for configurable sets of event types, source and target
addresses, and severity. You can apply multiple response rules for the same
event type when using either in-line mode or passive mode on the 7100 Series.
Response rules have no effect on sensor behavior.
Configurable responses include:
Console notification
Email or pager notification
SNMP trap
Traffic recording
TCP reset
TrackBack
Custom actions on the console or node
Some response actions, such as email or SNMP, can be tuned by configuring
related Network Security parameters.
This section provides procedures for:
Adding response rules
Deleting response rules
For a full description of all aspects of response rules, see the
Symantec Network
Security Administration Guide
.
Adding response rules
This section provides the basic procedure for adding a response rule in the
Network Security console. For more information about the available choices in
each step, see the
Symantec Network Security Administration Guide
.