Ips Quarantine Configuration In Policy Editors - McAfee M-1250 - Network Security Platform Configuration Manual

Ips configuration guide version 5.1
Hide thumbs Also See for M-1250 - Network Security Platform:
Table of Contents

Advertisement

McAfee® Network Security Platform 5.1
Note:
enabled IPS Quarantine for specific attacks in the IPS Policy Editor. Also, you need
to configure IPS Quarantine in the individual Sensor monitoring ports.

IPS Quarantine configuration in Policy Editors

In all the IPS Policy Editor, you can configure IPS Quarantine for individual attacks.
For successful quarantine and remediation of hosts, it is required that you enable IPS
Quarantine for each attack from the IPS Policy Editor. For more information, Enabling IPS
Quarantine in IPS Policy Editor (on page 109).
You can also enable IPS Quarantine in the other Policy Editors (Reconnaissance Policy
Editor or GARE), if required.
Enabling IPS Quarantine in IPS Policy Editor
As an example, configuration of IPS Quarantine for a particular attack in the IPS Policy
Editor is explained below. Note that you can optionally choose the Remediation option.
1
2
3
4
5
6
7
The Sensor successfully quarantine/ remediate hosts only if you have
From the Resource Tree, select
Select a policy, for example
View / Edit
Select
, to view the policy details.
Select any of the attack categories, say for example,
Select a protocol.
View/Edit
Select
. The list of attacks for the selected protocol is displayed.
Note:
You can search for attacks eligible for IPS quarantine from the
Attack Details
window. For more information, see Searching attacks eligible for
IPS Quarantine (on page 113).
Select the attack for which you need to enable quarantine (for example, here the
AFS:TCPDUMP Buffer Overflow
window for that particular attack is displayed.
Note:
You can select multiple attacks using the Bulk Edit option, and then
enable IPS Quarantine for all the selected attacks. For more information, see
Selecting multiple attacks for IPS Quarantine. (see "Selecting multiple attacks
for IPS Quarantine" on page 112)
IPS Settings > Policies > IPS Policy Editor
Default IDS
.
View / Edit
is chosen) and then click
109
Managing IPS settings
.
Exploit
.
Configure
Edit Attack Detail
. The

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network security platform

Table of Contents