Editing Acl Log Settings - McAfee M-1250 - Network Security Platform Configuration Manual

Ips configuration guide version 5.1
Hide thumbs Also See for M-1250 - Network Security Platform:
Table of Contents

Advertisement

McAfee® Network Security Platform 5.1
1
2
3
Computing Number of ACL rules utilized per Sensor
You can calculate the number of ACL rules being utilized per Sensor by adding all the
rules configured at the Sensor-level, port-level, and sub-interface level.
Example: Computing ACL rules utilized per Sensor
On an I-4010 Sensor, if you configure 8 rules at the Sensor level, 20 rules on port pair 2A-
2B, and 10 rules on the sub-interface of 4A-4B, you would have utilized 38 out of the 1000
limit.
You can also calculate the number of ACL rules utilized by adding the number of rules
displayed under
interface level.
Computing Number of ACL rules utilized during port clustering
When port clustering (interface grouping) is used, and port-level ACL rules are configured,
the number of ACL rules utilized (for each port-cluster-level ACL) will be different based on
the participant port-types of the cluster. One ACL rule will be consumed per each inline
port-pair member, and one ACL rule will be consumed per each SPAN port member of the
port cluster.
Examples: Computing the effective ACL rule utilization for each port-level ACL rule defined for a port-cluster
Port cluster 1: If your port cluster consists of 1A-1B (inline, fail-open), 2B (SPAN), and 4A-
4B (inline, fail-close), 3 ACL rules will be consumed for each ACL rule configured at the
port level.
Port cluster 2: If your port cluster consists of 1A (SPAN), 4A (SPAN), 5A (SPAN), 6A-6B
(inline, fail-close), 4 ACL rules will be consumed for each ACL rule configured at the port
level.

Editing ACL Log settings

ACL logging tracks the packets dropped / permitted based on your ACL rules.
logging per ACL
enabled.
To enable/disable ACL logging, do the following:
IPS Settings/Sensor_Name > ACL > ACL Assignments
Select
Effective ACL Rules
In the
tab, select an ACL rule.
View
Click
.
Effective ACL Rules
will generate logs only for traffic of ACL rules in which
tab at the Sensor level, each port level, and each sub-
186
The IPS Sensor_Name node
Enable ACL
ACL Logging
is

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network security platform

Table of Contents