Configuring Advanced Policies - McAfee M-1250 - Network Security Platform Configuration Manual

Ips configuration guide version 5.1
Hide thumbs Also See for M-1250 - Network Security Platform:
Table of Contents

Advertisement

McAfee® Network Security Platform 5.1
Steps:
1
2
3
The table below summarizes the scenarios discussed above.
Outside Network
Outside Network
Outside Network
Here are the high level steps to enable HTTP response inspection on a Sensor:
1
2
3
4
5
6

Configuring Advanced Policies

The
configuration of non-standard ports, rule set editor, Global attack response editor, UDS
editor, global auto acknowledgement, Incident Generation, export (policies) and import
(policies).
Figure 52: Tabs Under Advanced Policies
IPS Settings > Policies > HTTP Response Scanning
Go to
Sensor / IPS Failover Pair > HTTP Response Scanning
Outbound Status
Select 1A-1B under the
outbound traffic.
Inbound Status
Select 1A-1B under the
traffic.
1A
1B
Inside Network
Inside Network
Inside Network
Device List > Sensor_name > Physical Sensor > Port Settings
Under
settings for the ports on which you wish to enable HTTP response scanning .
IPS Settings > Policies > HTTP Response Scanning
Go to
Note:
HTTP response scanning can be enabled at the Sensor level from
Settings/Sensor_Name > IPS Sensor > HTTP Response Scanning
Pair node > IPS Failover Pair > HTTP Response Scanning.
Enable HTTP response processing as applicable to your network.
Apply
Click
.
IPS Settings > Configuration Update
Go to
Note:
Configuration Update can also be performed from
Sensor_Name > Configuration Update
Configuration Update.
Update
Click
.
Advanced Polices
tab under the IPS Setting node facilitates action related to
IPS Settings > Sensor_Name > IPS
or
page.
to enable HTTP response detection on
to enable HTTP response detection on inbound
Request From
Inside Network [ your employee
trying to access internet]
Outside Network [a hacker
trying to access your Web
server]
Inside and Outside Network
page.
page.
IPS Settings / Failover_Pair_Name_Node >
or
50
Managing IPS settings
HTTP Response Scan
to be Enabled
Outbound
Inbound
Inbound and
Outbound
page, verify the port
IPS
IPS Settings/Failover
and
IPS Settings >

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network security platform

Table of Contents