Setting Policy For Interfaces And Sub-Interfaces; Using Virtualization For Policy Application; The Ips Sensor Interface Node - McAfee M-1250 - Network Security Platform Configuration Manual

Ips configuration guide version 5.1
Hide thumbs Also See for M-1250 - Network Security Platform:
Table of Contents

Advertisement

McAfee® Network Security Platform 5.1
1
2
3

Setting policy for interfaces and sub-interfaces

Network Security Sensors allow for very granular policy application and enforcement:
multiple IPS and denial of service policies can be enforced on a single port or port pair.
For example, suppose you are a Super User at the root admin domain level, and you
deploy a single Sensor. You edit the details of your root domain and decide to keep the
Default Inline IPS
the Sensor, the
Sensor and all of the Sensor's interfaces by default.
Note:
page 7).

Using Virtualization for policy application

Current Sensor-based IDS products permit you to apply only one security policy for the
entire Sensor. However, if you have multiple segments to monitor or you need to monitor
aggregated traffic—like on Gigabit uplinks—a multi-port box and more granularity in the
inspection process makes for a much more cost effective and efficient security solution.
Thus, McAfee
feature.
The VIPS feature enables you to configure multiple policies for multiple unique
environments all monitored with a single Network Security Sensor.
Note:
sections I-series Sensor capacity by model number, and M-series Sensor capacity
by model number in
For information on setting policies for interfaces and sub-interfaces, see Setting
policy for interfaces and sub-interfaces (on page 213).

The IPS Sensor interface node

The
interface group) on a particular Sensor. The number of interface nodes displayed depends
upon the type of Sensor. Interface nodes are displayed individually by default because the
default monitoring mode is SPAN mode.
Item
Interface Nodes, Port Pairs
Interface Nodes, Single Ports
Sub-interface Node
policy that is applied by default upon Manager installation. When you add
Default Inline IPS
For more information on policies, see Configuring and managing policies (on
®
Network Security Platform's Virtual Intrusion Prevention System (VIPS)
For more information on the maximum Virtual interfaces per Sensor, see the
Troubleshooting Guide
Interface-x
nodes represent an interface (a single physical port, peer ports, or an
Description
policy is inherited from the root domain and applies to the
.
213
The IPS Sensor_Name node

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network security platform

Table of Contents