Firewall Protection Mode And Detections Of Unknown Applications - McAfee TSA00M005PAA - Total Protection Service Product Manual

Processor guide
Hide thumbs Also See for TSA00M005PAA - Total Protection Service:
Table of Contents

Advertisement

Using Firewall Protection

Firewall protection mode and detections of unknown applications

Firewall protection mode and detections of
unknown applications
Firewall protection monitors communications with Internet applications, which connect to the
Internet and communicate with client computers. When it detects an Internet application
running on a computer, it either allows the application to connect to the Internet or blocks the
connection. The response is based on the firewall protection mode selected in the policy
assigned to the client computer.
In this mode...
In this mode...
Protect
Protect
Prompt
Prompt
Report
Report
For all modes, detections are reported to the SecurityCenter, where you can view information
about them in reports.
NOTE:
To prevent popup prompts from appearing on client computers when applications are
detected, and for highest security, we recommend using Protect mode.
How policy options are implemented in the three protection modes
Use the following table to determine how policy options are implemented in the different
protection modes.
Mode
Mode
Report
Report
Prompt
Prompt
Protect
Protect
NOTE:
If the policy is changed from Prompt mode to Protect mode or Report mode, firewall
protection saves user settings for allowed applications. If the policy is then changed back to
Prompt mode, these settings are reinstated.
McAfee Total Protection Service Product Guide
Firewall protection does this...
Firewall protection does this...
Blocks the suspicious activity.
Blocks the suspicious activity.
Displays a dialog box with information about the detection, and allows the user to select
Displays a dialog box with information about the detection, and allows the user to select
a response. This setting is the default.
a response. This setting is the default.
Sends information about suspicious activity to the SecurityCenter and takes no additional
Sends information about suspicious activity to the SecurityCenter and takes no additional
action.
action.
Behavior of firewall protection
Behavior of firewall protection
Users are not prompted about detections.
Users are not prompted about detections.
Detections are reported to the SecurityCenter.
Detections are reported to the SecurityCenter.
Administrator can select allowed applications, which are not reported as detections.
Administrator can select allowed applications, which are not reported as detections.
Can be used as a "learn" mode to discover which applications to allow and block.
Can be used as a "learn" mode to discover which applications to allow and block.
Users are prompted about detections.
Users are prompted about detections.
Detections are reported to the SecurityCenter.
Detections are reported to the SecurityCenter.
Administrator can select allowed applications. These applications are not reported
Administrator can select allowed applications. These applications are not reported
as detections, and users are not prompted for a response to them.
as detections, and users are not prompted for a response to them.
Users can approve additional applications in response to prompts. These are reported
Users can approve additional applications in response to prompts. These are reported
to the SecurityCenter.
to the SecurityCenter.
Users are not prompted about detections.
Users are not prompted about detections.
Users are notified about blocked applications.
Users are notified about blocked applications.
Detections are reported to the SecurityCenter.
Detections are reported to the SecurityCenter.
Administrator can select allowed applications, which are not reported as detections.
Administrator can select allowed applications, which are not reported as detections.
85

Advertisement

Table of Contents
loading

Table of Contents