Managing Rule Sets With The Rule Set Editor - McAfee M-1250 - Network Security Platform Configuration Manual

Ips configuration guide version 5.1
Hide thumbs Also See for M-1250 - Network Security Platform:
Table of Contents

Advertisement

McAfee® Network Security Platform 5.1
1
2
3
4
5
6
Note:
from
Pair Node >Advanced Scanning >Non-standard Ports.
node from
deleted or edited from the Sensor_Name or failover pair node. Only ports that are
added from the Sensor_Name or failover pair nodes can be edited or deleted from
these nodes.

Managing rule sets with the Rule Set Editor

The
environment resources you want to protect. A rule set consists of select attacks specific to
a network environment, such as the operating system(s) you employ, the installed
applications (email, chat), and the transport and application protocols (HTTP, FTP) used
for data delivery. The protocol field includes all of the attacks detected by Network Security
Platform for specific selection by attack name, severity, and the chance a signature may
trigger a false positive. Each rule you configure narrows the detection focus of your Sensor
interfaces (where policy is applied) to provide the highest degree of detection accuracy
and performance.
The Rule Set Editor provides the following functions:
Viewing a rule set
To view a pre-configured or custom rule set, do the following:
1
2
Adding a rule set
The Rule Set Editor enables you to create a set of rules that must be detected (included)
or ignored (excluded) during the detection process. The Include and Exclude rules are
IPS Settings > Advanced Policies > Non-standard Ports
Click
Select an entry.
Edit
Click
.
Select the non-standard port to delete.
Delete
Click
; confirm deletion by clicking
Download your changes to your Sensors by performing the steps in Updating the
configuration of all Sensors (on page 154).
Non-standard ports can be added at the Sensor name or failover pair nodes
IPS Settings/Sensor_Name >Advanced Scanning >Non-standard Ports
IPS Settings > Advanced Policies > Non-standard Ports
Rule Set Editor
action enables the use of a powerful tool for defining the exact
Viewing a rule set from the Rule Set Editor (on page 53)
Adding a rule set (on page 53)
Cloning a rule set (on page 60)
Editing a rule set (on page 61)
Deleting a rule set (on page 61)
IPS Settings > Advanced Policies > Rule Set Editor.
Click
Select a rule set row and click
Note:
The rule set information takes a few seconds to load and display.
.
OK
.
The ports added at the IPS Settings
can not however be
View / Edit
.
53
Managing IPS settings
IPS Settings/Failover
or

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network security platform

Table of Contents