Ips Quarantine Settings - McAfee M-1250 - Network Security Platform Configuration Manual

Ips configuration guide version 5.1
Hide thumbs Also See for M-1250 - Network Security Platform:
Table of Contents

Advertisement

McAfee® Network Security Platform 5.1
1
2
3
4
5
6
7
8
Deleting SSL key files from Manager
To delete escrowed SSL key files from Manager, do the following:
1
2
3

IPS Quarantine settings

To protect your network from security threats, McAfee
the IPS Quarantine feature which quarantine and remediate the non-compliant network
devices (or hosts) connecting to your network.
When the Sensor detects attacks from a host on its configured monitoring port, a
quarantine rule is created for the source IP address of the host. The host is now in
quarantine. Thereafter, the Sensor drops any traffic from the host until the quarantine rule
expires. Thus quarantine action prevents non-compliant hosts from harming other network
systems, by isolating them from the network for a specified period of time.
The quarantined host is allowed to access certain IP addresses and denied access to
specific IP addresses until it is remediated. You can specify the IP addresses which need
to be accessed/denied in IPS Quarantine Network Access Zones.
The quarantined host can be remediated by re-directing the HTTP traffic from the host to a
Remediation Portal server. During remediation, the host is made compliant with the
security policies of your network.
The state of the host, that is whether the host is in Quarantine/ Remediation, can be
viewed from the Threat Analyzer window.
Note:
mode.
Following configurations are required for IPS Quarantine, in the Manager:
IPS Settings > SSL Decryption > Key Management
Click
Select the radio button in the
Re-import
Click
.
Passphrase
Type the
related to the PKCS12 file.
Locate the key PKCS12 File on your client system by clicking
Apply
Click
. A pop-up window details import status.
Download the changes to the Sensor.
The changes are updated in the Sensor as explained in Updating the configuration of
all Sensors (on page 154).
IPS Settings > SSL Decryption > Key Management
Click
Select the radio button in the
Delete
Click
. Confirm the deletion.
IPS Quarantine works only when the Sensor monitoring ports are in inline
IPS Quarantine configuration in Policy Editors (on page 109)
IPS Quarantine configuration in Admin Domain (on page 115)
IPS Quarantine configuration in the IPS Sensor (on page 209)
IPS Quarantine settings in the Threat Analyzer (on page 123)
.
Configuration Update
column for the desired Sensor.
.
Configuration Update
column for the desired Sensor.
®
Network Security Platform provides
108
Managing IPS settings
Browse
.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network security platform

Table of Contents