General Settings Tab - Enterasys Intrusion Prevention System Manual

Network sensor policies and signatures guide
Hide thumbs Also See for Intrusion Prevention System:
Table of Contents

Advertisement

Configuring the Application Filter Module

General Settings Tab

Use the settings on the General Settings tab to configure the sensor to ignore traffic based on
direction with respect to the sensor's protected network.
The sensor can ignore traffic that is:
Entirely within the protected network (both source and destination addresses inside protected
network)
Entirely external to the protected network (both source and destination addresses outside of
protected network)
From the protected network (only source address within protected network)
To the protected network (only destination address within protected network)
You can potentially improve performance by watching only the traffic that is coming into or out of
your protected networks and ignoring internal traffic. For example, if you have a lot of internal
network traffic such as NFS, Microsoft file sharing, or internal DNS lookups, then ignoring
internal traffic will result in a noticeable performance increase. With Linux, the performance
increase will result from Enterasys IPS's quick decision to drop internal packets.
Ignoring all entirely external packets to the protected networks allows the Network Sensor to
concentrate only on packets that involve the protected network in some way.
Ignoring all packets sourced within the protected networks and destined for IP addresses not in
the protected networks allows the sensor to concentrate on packets entering the set of protected
network ranges.
Ignoring all packets with a destination IP address in the protected networks and a source IP
address not in the protected networks allows the sensor to concentrate on packets leaving the set
of protected ranges.
Procedure
To configure general settings:
1.
Click the Network Policy View icon, and then the Network Policies tab.
2.
Expand the tree by clicking on the expansion symbol, then select the custom policy name.
The modules for that policy are displayed in the tree.
3.
Click the Application Filter Module in the tree. The Application Filter Module settings
display in the right pane.
2-4 Creating Network Sensor Policies

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the Intrusion Prevention System and is the answer not in the manual?

Table of Contents