Viewing The Dos Detection Status Of A Sensor - McAfee M-1250 - Network Security Platform Configuration Manual

Ips configuration guide version 5.1
Hide thumbs Also See for M-1250 - Network Security Platform:
Table of Contents

Advertisement

McAfee® Network Security Platform 5.1
1
2
The table below summarizes the scenarios discussed above.
Outside Network Inside Network
Outside Network Inside Network
Outside Network Inside Network
Here are the high level steps to enable HTTP response inspection on a Sensor:
1
2
3
4
5
6

Viewing the DoS detection status of a Sensor

The
applied to a Sensor, as well as its interfaces and sub-interfaces. In DoS Learning Mode, a
profile is built to determine a "normal" traffic pattern. Once this profile is learned, the
Sensor alerts for traffic that is outside of the normal parameters. The profile is continually
being built, thus baseline levels adjust over time.
The "Applied Policy Detail" table displays the parent-child (Sensor-interface) relationship
with Learning Mode status values for the Sensor and each interface, respectively. This is
particularly useful if you have changed policy application per interface and you want to
determine if the new profile is being built or if it is actively detecting abnormal traffic
conditions.
Tip:
creating a custom DoS policy using the
sub-interface level.
Device List > Sensor_name > Physical Sensor > Port Settings
Go to
Verify that port 1A is connected to
1A
1B
Device List > Sensor_name > Physical Sensor > Port Settings
Under
settings for the ports on which you wish to enable HTTP response scanning .
IPS Settings > Policies > HTTP Response Scanning
Go to
Note:
HTTP response scanning can be enabled at the Sensor level from
Settings/Sensor_Name > IPS Sensor > HTTP Response Scanning
Pair node > IPS Failover Pair > HTTP Response Scanning.
Enable HTTP response processing as applicable to your network.
Apply
Click
.
IPS Settings > Configuration Update
Go to
Note:
Configuration Update can also be performed from
Sensor_Name > Configuration Update
Configuration Update.
Update
Click
.
DoS Detection Status
action displays the current status of DoS Learning Mode policies
Denial of service (DoS) parameters are configured within each IPS policy or by
Outside Network
and 1B is connected to
Request From
Outside Network [a
hacker trying to access
your Web server]
Inside Network [ your
employee trying to
access internet]
Inside and Outside
Network
page.
page.
IPS Settings / Failover_Pair_Name_Node >
or
Custom DoS Policy
action at the interface or
162
The IPS Sensor_Name node
page.
Inside Network
HTTP Response
Scan to be Enabled
Inbound
Outbound
Inbound and
Outbound
page, verify the port
IPS
IPS Settings/Failover
and
IPS Settings >
.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network security platform

Table of Contents