Managing Alert Filters And Attack Responses; Using The Alert Filter Editor - McAfee M-1250 - Network Security Platform Configuration Manual

Ips configuration guide version 5.1
Hide thumbs Also See for M-1250 - Network Security Platform:
Table of Contents

Advertisement

McAfee® Network Security Platform 5.1
2
Completing the policy import
To complete policy import:
1
2

Managing alert filters and attack responses

You can create alert filters at the IPS Settings node. The Manager applies alert filters at
the interface/sub-interface levels only. Alert Filters associated at the IPS Settings node for
a domain level get associated with all Sensors belonging to that Domain. Similarly, alert
filters associated at the Sensor are associated with all interface/sub-interface belonging to
that Sensor.
Figure 86: Alert Filters Tab
To use alert filters, select IPS Settings at the Admin Domain, Sensor, Interface, or Sub-
interface level and go to the
You can perform the following tasks:

Using the Alert Filter Editor

To manage Alert Filters using the Alert Filter Editor, select
From this page, you can perform the following tasks:
displayed (with diff details) in the utility. This indicates that there are more than
100 differences in that section.
Note 2:
If the Outbound Policy is configured for one of the policies, then, the
Outbound Policy details are not displayed - only name is displayed.
Note 3:
Only alert filter names are compared in the utility; alert filter definitions
are not compared, as they are not part of the Policy definition.
Close the Policy Diff window to return to the
Select the policies that you want to import and click
IPS Settings > IPS Settings > Summary
Select
Alert Filters
Edit alert filters: This includes adding, cloning, viewing, and deleting alerts. See Using
the Alert Filter Editor (on page 78).
Manage alert filter assignments: See Alert filters assignments (on page 82).
Export alert filter: See Exporting alert filters (on page 84).
Import alert filter: See Importing alert filters (on page 84).
Add alert filters (on page 79)
Clone alert filters (on page 81)
Import Policy Difference Status
Apply
to verify successful policy import.
tab.
78
Managing IPS settings
screen.
.
IPS Settings > Alert Filters
.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network security platform

Table of Contents