Managing Dos Filters - McAfee M-1250 - Network Security Platform Configuration Manual

Ips configuration guide version 5.1
Hide thumbs Also See for M-1250 - Network Security Platform:
Table of Contents

Advertisement

McAfee® Network Security Platform 5.1
Figure 179: Uploading A DoS Profile From A Sensor To The Manager
Figure 180: Restoring A DoS Profile

Managing DoS filters

The
that have been initiated for the DoS Learning Mode profiles applied for all network
identifiers (NIs) within a Sensor. A DoS filter, or blocking rule, is similar to a firewall deny
rule in that subsequent traffic that matches the filter parameters is blocked from
transmitting further through your network. A network identifier is a Network Security
Platform term relating to interface, sub-interface, and DoS ID resources. DoS filters are
applied exclusively to DoS Learning Mode attacks.
A DoS filter can be initiated for any DoS Learning Mode attack, namely the measures
within each attack. Each enabled Learning Mode attack is a combination of traffic flow rate
measures, such as the rate of TCP control packets or UDP packets. When a Learning
Mode profile has completed learning the normal traffic behavior, the long-term measure
volumes in this profile are matched against short-term volume calculations for each
Manage DoS Profiles
Click
file. One file is uploaded for all interfaces, sub-interfaces, or DoS IDs of a
Sensor. This file is listed in the "DoS Profiles Uploaded from Sensor to
Manager" section (top) of the table.
Note :
You will have to wait at least two days for the first learning profile to
finish before you can download a profile.
Restore DoS Profile from Manager to Sensors
that has been previously uploaded (saved) to Manager using the
from Sensor to Manager
option. The uploaded profile is listed under the "DoS Profiles
Uploaded from Sensor to Manager" heading. To restore a DoS profile, do the
following:
Restore DoS Profile from Manager to Sensors
Select
Apply
Click
.
Select a DoS profile and click
(Optional) Select a DoS profile and click
(Optional) Select a DoS profile and click
to a client that is not Manager server.
DoS Filters
action enables you to view and modify the "drop/block packets" responses
to return to the main screen to view your uploaded
: downloads a DoS profile to the Sensor
Restore
.
Delete
Export
168
The IPS Sensor_Name node
Upload DoS Profile
.
to delete the profile.
to export and save the profile

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network security platform

Table of Contents