
These options are available...With this policy...
AllIPS Client Rules
AllSearch IPS Exception Rules
NoneHIP 7.0 FIREWALL
NoneHIP 7.0 APPLICATION BLOCKING
Notes about the Linux client
• If you have an existing SELinux policy in place or are using default protection settings,
installing a Linux client replaces the policy with a default McAfee Host Intrusion Prevention
policy. Uninstalling the Linux client restores the previous SELinux policy.
• The Linux client requires that SELinux be installed and enabled (set to enforce or permissive).
If it is installed but disabled, enable it, set it to targeted policy, and restart the computer
before installing the Linux client.
• Linux controls file attribute changes with a single SELinux permission (file:setattr). It does
not have individual control of chdir or symlink, control of changing directory, or control of
creating a symbolic link.
• SELinux uses a mandatory access control mechanism implemented in the Linux kernel with
the Linux Security Modules (LSM) framework. This framework checks for allowed operations
after standard Linux discretionary access controls are checked. Because the Linux client uses
LSM, any other application that uses LSM will not work unless stacking is implemented.
Linux client issues
After the Linux client is installed and started, it protects its host. However, you may need to
troubleshoot installation or operation issues.
Linux client installation issues
If a problem was caused while installing or uninstalling the client, there are several things to
investigate. These can include ensuring that all required files were installed in the correct
directory, uninstalling and then reinstalling the client, and checking process logs.
Linux client operation issues
The client might be installed correctly, but you might encounter problems with the operation
of the client. You can check whether the client is running, and stop and restart the client.
Verifying Linux installation files
After an installation, check to see that all the files were installed in the appropriate directory
on the client. The opt/McAfee/hip directory should contain these essential files and directories:
DescriptionFile Name
Linux clientHipClient; HipClient-bin
Policy rulesHipClientPolicy.xml
Troubleshooting toolhipts; hipts-bin
Working with Host Intrusion Prevention Clients
Overview of the Linux client
103McAfee Host Intrusion Prevention 7.0 Product Guide for use with ePolicy Orchestrator 4.0
Comentarios a estos manuales