Symantec 10521148 Implementation Guide - Page 133

Insert Response Rule, Duplicate Response Rule

Page 133 highlights

Configuring detection and response 125 About response rules Note: It can take a few minutes for response rule changes to take effect. You can bypass the wait interval by clicking Admin > Force Database Sync. To add or insert a response rule 1 In the Network Security console, click Configuration > Response Rules. 2 In Response Rules, do one of the following: ■ Click Action > Add Response Rule to add a new row to the end of the response rules table. ■ Click Action > Insert Response Rule to insert a new row into the response rules table. ■ Click Action > Duplicate Response Rule to add a copy of an existing row to the response rules table. 3 Click the Event Target cell of the response rules table row. 4 In Select Event Target, select the location(s), network segment(s) and/or peer interfaces to which the response rule will apply, and click OK. 5 Click the Event Type cell of the response rule. 6 In Select Events, select the attack types to which the response rule applies, and click OK. 7 Click the Severity cell of the response rules table row. 8 Select a symbol (, =) and a severity level from the pop-up list, and click OK. 9 Click the Confidence cell of the response rules table row. 10 Select a symbol (, =) and a severity level from the pop-up list, and click OK. 11 Click the Event Source cell of the response rules table row. 12 In Select Event Source, select the interfaces to which the response rule applies. 13 Set VLAN if applicable, and click OK. 14 Click the Response Action cell of the response rules table row. 15 In Configure Response Action, select an action for Network Security to take if the event matches the response rule. 16 Select a Next Action to do one of the following: ■ Stop searching for matching response rules. ■ Continue to the next rule.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214

125
Configuring detection and response
About response rules
Note:
It can take a few minutes for response rule changes to take effect. You can
bypass the wait interval by clicking
Admin
>
Force Database Sync
.
To add or insert a response rule
1
In the Network Security console, click
Configuration
>
Response Rules
.
2
In
Response Rules
, do one of the following:
Click
Action
>
Add Response Rule
to add a new row to the end of the
response rules table.
Click
Action
>
Insert Response Rule
to insert a new row into the
response rules table.
Click
Action
>
Duplicate Response Rule
to add a copy of an existing
row to the response rules table.
3
Click the
Event Target
cell of the response rules table row.
4
In
Select Event Target
, select the location(s), network segment(s) and/or
peer interfaces to which the response rule will apply, and click
OK
.
5
Click the
Event Type
cell of the response rule.
6
In
Select Events
, select the attack types to which the response rule applies,
and click
OK
.
7
Click the
Severity
cell of the response rules table row.
8
Select a symbol (<, >, =) and a severity level from the pop-up list, and click
OK
.
9
Click the
Confidence
cell of the response rules table row.
10
Select a symbol (<, >, =) and a severity level from the pop-up list, and click
OK
.
11
Click the
Event Source
cell of the response rules table row.
12
In
Select Event Source
, select the interfaces to which the response rule
applies.
13
Set VLAN if applicable, and click
OK
.
14
Click the
Response Action
cell of the response rules table row.
15
In
Configure Response Action
, select an action for Network Security to take
if the event matches the response rule.
16
Select a
Next Action
to do one of the following:
Stop searching for matching response rules.
Continue to the next rule.