Assigning Acl Rules In The Ips Sensor - McAfee M-1250 - Network Security Platform Configuration Manual

Ips configuration guide version 5.1
Hide thumbs Also See for M-1250 - Network Security Platform:
Table of Contents

Advertisement

McAfee® Network Security Platform 5.1
The IPS Sensor_Name node
Note:
To view the anti-spoofing configurations of a Sensor, you can generate the
Reports Guide
ACL Assignments Report. For more information on this report, see the
.
Figure 189: ACL Tab

Assigning ACL rules in the IPS Sensor

A Sensor ACL is useful for maximizing a Sensor's detection and prevention capabilities by
denying specified traffic without requiring full inspection, while also permitting certain traffic
to pass without inspection.
At the Sensor level, you can assign rules for the entire Sensor as well as those for specific
ports/port pairs of the Sensor. Rules assigned at the Sensor level for a specific port/port
pair are inherited by all the ports/interfaces/sub-interfaces, while rules assigned are
inherited by the corresponding interface and, if applicable, sub-interface( s). In the case of
ACLs, an interface is a subset of the corresponding port or port pair. That is, ACL rules
configured for a port/port pair at the Sensor level are inherited by the corresponding
interface as well as any sub-interfaces. However, ACL rules created at the interface level
are not inherited by corresponding sub-interfaces due to the rule of separating interface
traffic flows from sub-interface traffic flows based on the following policy application rule:
If you configure multiple ACL rules, note the order as ACLs are executed in top-down
sequence: the rule at the top of the list is checked first, followed in order by subsequent
rules down to the bottommost rule. Network Security Platform employs a first-match
process; the first ACL rule matched in sequence is enforced.
If you apply a policy to a sub-interface that is different than the inherited policy, the policy
enforced at the interface level protects all traffic not specific to the sub-interface. Thus, for
ACL rules, the rule of inheritance requires you to create global rules at the Sensor or
physical port/port pair level: interface rules only apply to interfaces, and sub-interface rules
only apply to sub-interfaces.
181

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network security platform

Table of Contents