Enabling Ssl Decryption - McAfee M-1250 - Network Security Platform Configuration Manual

Ips configuration guide version 5.1
Hide thumbs Also See for M-1250 - Network Security Platform:
Table of Contents

Advertisement

McAfee® Network Security Platform 5.1
The IPS Sensor_Name node
internal network. Similarly, when the response HTTP traffic passing port 1A from the
internal network, exceeds the configured rate limiting value of 5120 Kbps, the Sensor rate
limits the traffic by dropping excess data packets. Only the configured traffic bandwidth
value of 5120 Kbps is allowed to pass through port 1A to the Internet.
Network Scenario for DiffServ tagging
Consider a network scenario where the internal network of a University is connected to the
internet, and Network Security Platform and the router are deployed as shown in the below
diagram.
Figure 203: Scenario For DiffServ Tagging
Suppose you want to prioritize the HTTP and P2P traffic coming from the University
network to the internet. To prioritize the traffic, you can configure the Sensor for DiffServ or
VLAN tagging. The role of the Network Security Sensor is just to tag the packets and pass
it on to an external network device (here router) for DiffServ or VLAN classification.
Suppose you want to give high priority to the HTTP traffic coming from the University
network to the internet. You can configure the Sensor port 1B with a DiffServ rule, in which
the DiffServ field is set to a value, say 60, for HTTP traffic. When the HTTP traffic from the
University network reaches Sensor port 1B, the Sensor tags the packet headers with the
DiffServ field value specified in the configuration (60, in this example). The tagged packets
are sent to the router, which is configured to do DiffServ categorization. Now the traffic is
prioritized as per the DiffServ priority defined in the router. Note that the Sensor only tags
the incoming traffic and passes it on to the external network device (in this case, it is the
router) which further performs the DiffServ classification.
Similarly, to provide low priority to the P2P traffic coming from the University network to the
internet, you can configure port 1B of the Sensor with a DiffServ rule, in which the DiffServ
field is set to a value, say 5. When the P2P traffic from the University network reaches
Sensor port 1B, the Sensor tags the packet headers with the DiffServ field value specified
in the configuration (5, in this example). The tagged packets then reach the router which
performs DiffServ classification and prioritization, based on the rules configured in the
router.

Enabling SSL decryption

Sensor_Name > SSL Decryption
The
tab contains the actions required to enable Secure Socket
Layer (SSL) decryption on a Sensor, as well as to import and manage the SSL keys the
Sensor uses for decryption.
204

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network security platform

Table of Contents