
McAfee Default policy
(continued)
Host Intrusion Prevention 9
McAfee recommendations
contact McAfee support to disable HIPS engine 90
duplicate a policy before assigning to a group 10
for VPN connections, set quarantine rules 55
group Host IPS clients logically 18
group systems by Host IPS criteria 10
phased Host IPS deployment 18
tune Host IPS default policies 18
use IPS Protection to stagger impact of events 11
monitored processes, viewing 97
My Default policy
Application Blocking 70
Application Blocking Rules 71
Client UI 77
Firewall Options 56
Firewall Rules 57
Host Intrusion Prevention 9
Quarantine Options 64
Trusted Applications 82
Trusted Network 81
N
network adapters
allowed types, stateful firewall 50
conditions to allow connection 50
network intrusion prevention signatures 25
network layers and protocols, illustrated 45
network signatures 31
NIPS (network intrusion prevention signatures) 24, 96
notifications, Host IPS
about 21
configuring 18
event categories 21
rules and events 21
supported product-specific categories 22
O
operating systems
host and network IPS, signatures 24
IPv6 and stateful functionality 45
out-of-the-box protection
default Host IPS policies 16
Host IPS basic 8
preset Host IPS policies 11
P
packages
Host IPS content updates 22
packet filtering and inspection 45, 46
passwords
for Client UI policy 78
unlocking the Windows client console 87
using hipts troubleshooting tool 100
permission sets
Host IPS permissions 20
managing Host IPS deployment 20
who configures the system 18
policies, Host IPS
and their categories 9
Application Blocking Options 70
application blocking, customizing 96
assigned owner 10
policies, Host IPS
(continued)
client rules, creating exceptions 11
configuring IPS Options 27
defaults, basic protection 8
defined 9
firewall (See firewall, Host IPS) 8
Firewall Options 56, 57
Firewall Rules 57, 59
how policies are applied 10
how policies are enforced 9
intrusion prevention (IPS) 8
managing 17
overriding, with client exceptions 11
overview of features 8
ownership 8
Policy Catalog 17
preset protection 11
Quarantine Options 55, 64
Quarantine Options policy 92
Quarantine Rules 65
trusted applications 8
tuning defaults 18
usage profiles and tuning 11
viewing policies 17
where to find 17
policy assignment
editing Application Blocking Options 70
Host IPS and 10
working with Firewall Options 56
Policy Catalog
Application Blocking 70
Application Blocking Options 70
Application Blocking Rules 71
Client UI 77
custom firewall policies, creating 56, 57
managing Host IPS policies 17
ownership for Host IPS policies 8
Quarantine Options 64
Trusted Applications 82
Trusted Network 81
Trusted Networks 81
policy enforcement
Host IPS and 9
Host IPS clients and ePO 7
Linux client and 102
Solaris client and 99
policy management
accessing Host IPS policies 17
analyzing Host IPS events and client rules 16
Host IPS extension file 9
Linux client and 102
Policies tab, Host IPS 17
tracking Host IPS policies 10
tuning Host IPS 10, 11, 16
ports
blocked traffic and firewall rules 54
connections and firewall alerts 91
firewall and state table entries 47
FTP connections and stateful packet inspection 49
precedence
firewall rules list 47
General policies, Host IPS and 76
Network IPS and IP addresses 81
Trusted Networks policy 81
preconfigured policies
Application Blocking 70
Index
109McAfee Host Intrusion Prevention 7.0 Product Guide for use with ePolicy Orchestrator 4.0
Commentaires sur ces manuels