
preconfigured policies
(continued)
Application Blocking Rules 71
Client UI 77
Firewall Rules 57
IPS Options 27
IPS Protection 28
Quarantine Options 64
Trusted Applications 82
Trusted Network 81
Property Translator task 21
protocols
tracking, and stateful firewall 49
Q
Quarantine Options policy
about 8, 55
alerts 92
configuring 64
working with 64
quarantine rules
about 8
alerts, responding to 92
configuring 65
creating and editing 66
policies and rules 55
predefined, adding 68
rule groups, creating and editing 66, 67
Quarantine Rules policy
about 8
working with 65
queries, Host IPS
custom, parameters for 14
managing information 13
predefined and custom 14
reports 12
tracking activities 13
Query Builder wizard
Host IPS queries 14
R
reactions
about 26
application blocking alerts, responding to 92
firewall alerts, responding to 91
intrusion alerts, responding to 90
IPS Protection, configuring 28
mapping to IPS severity 11
quarantine alerts, responding to 92
setting, for signature severity levels 29
spoof detected alerts, responding to 92
types of 26
rule groups, Host IPS firewall 50
rules lists
application rules list 96
exceptions for Host IPS 93
firewall rules for Host IPS 95
S
security levels
types of 30
SELinux (See Linux client) 103
server tasks, Host IPS
checking in updates 23
managing deployment 20, 21
server tasks, Host IPS
(continued)
Property Translator 21
severity levels, IPS
events and 40
IPS Protection policy 28
mapping to a reaction 11
setting and tuning protection 16
setting reactions for 29
signatures 24
tuning 11, 18
working with signatures 30
signatures
alerts and NIPS signatures 91
configuring IPS Rules policy 32
creating custom host intrusion prevention signatures 33
creating with expert method 33
creating with standard method 33
custom 31
default host IP signatures 31
defined 24
exception rules 26
exception rules list 93
HIPS, about 25
host 31
host and network IPS 22, 24
host IP, and exceptions 90
IPS Rules policy 30
network 31
NIPS, about 25
severity levels 30
severity levels for 28
tuning Host IPS policies 11
types of 31
using the wizard to create 34
working with 30
Solaris client
installation files 100
overview 99
policy enforcement 99
preventing buffer overflow 99
stopping and restarting 101, 102
troubleshooting 100
verifying client is running 100
Spoof Detected alerts 92
state table, firewall
functionality 47
overview 47
stateful filtering 55
stateful filtering
adaptive and learn modes 55
overview 46
state table 55
stateful firewall
how stateful filtering works 48
packet inspection, how it works 49
protocol tracking 49
system management
notifications for Host IPS events 21
server tasks for Host IPS 20, 21
updating Host IPS protection 22
system tray icon
client status indicator 86
disabling a Host IPS feature 79
setting client options 87
McAfee Host Intrusion Prevention 7.0 Product Guide for use with ePolicy Orchestrator 4.0110
Index
Comentarios a estos manuales