Nac Acl Logging In The Sensor For Ips Quarantine - McAfee M-1250 - Network Security Platform Configuration Manual

Ips configuration guide version 5.1
Hide thumbs Also See for M-1250 - Network Security Platform:
Table of Contents

Advertisement

McAfee® Network Security Platform 5.1

NAC ACL Logging in the Sensor for IPS Quarantine

Following steps explain NAC ACL Logging configurations for the Sensor from the Manager
user interface:
1
Figure 209: Configuring NAC ACL logging settings
2
3
When you enable NAC ACL Logging, note that you need to enable the Syslog server as
well. Before selecting the second and third options (b and c) above, a pop-up is displayed
asking if Syslog Forwarding should be enabled. When you select Yes, you will be re-
directed to the Syslog Server settings page under IPS Settings > IPS Quarantine for the
admin domain. This step is required to view the generated NAC ACL logs. For more
information on configuring the Syslog Server, see Configuring Syslog messages for IPS
Quarantine (on page 119).
In the Resource Tree, select
Logging
.
This page in the Manager helps you to edit the NAC ACL Logging settings for the
Sensor monitoring port.
Following options are available for NAC ACL Logging:
Disable Logging
– This option disables the NAC ACL Logging.
a.
Log per NAC ACL Only
– This option is to generate alert logs for each NAC ACL.
b.
When you configure a NAC ACL, the configuration page for each NAC ACL entry
displays an option to enable/disable NAC ACL Logging for the entry. The logging
is enabled/ disabled accordingly.
Log Sensor- wide
– There are three Sensor-wide configurations for NAC ACL
c.
Logging.
Log all Allowed Traffic
i.
generated only for those ACLs for which traffic is configured to pass through
the Sensor.
Log all Blocked Traffic
ii.
generated only for those ACLs for which traffic is configured to be blocked by
the Sensor.
Log both Blocked and Allowed Traffic
iii.
logs are generated for ACLs for which traffic is configured to be allowed or
blocked by the Sensor.
Commit Changes
Select
, to save the NAC ACL Settings on the Sensor.
IPS Settings > IPS Sensor_Name > IPS Quarantine > NAC ACL
– When you select this option, NAC ACL alert logs are
– When you select this option, NAC ACL alert logs are
– When you select this option, NAC ACL alert
210
The IPS Sensor_Name node

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network security platform

Table of Contents