
IPS Client RulesFirewall Client RulesApplication Blocking Client Rules
• Non-IP Protocol
• Process Eval Option
• Process Name
• Process Path
• Props schema ID
• Reaction
• Remote Address
• Remote Address Type
• Remote Service
• Rule Name
• Start Time
• Switch When Expired
• Time Restriction
• Time Task
In addition, you can create queries using these Host IPS properties:
• Firewall Status• Agent type
• Application Blocking Adaptive Mode Status • IPS Status
• Install Directory• Application Blocking Learn Mode Status
• Application Blocking Status • IPS Adaptive Mode Status
• Language• Blocked Attackers
• Client Version • Local Exception Rule Count
• NIPS Status• Content Version
• Firewall Adaptive Mode Status • Plug-in Version
• Product Status• Firewall Inbound Learn Mode Status
• Firewall Outbound Learn Mode Status • Service Running
• Firewall Rule Count
Pre-defined queries
Select from these Host IPS queries:
SummaryHIP Query
Displays where Application Blocking Creation is enabled on managed systems.App Block Create Status
Displays where Application Blocking Hooking is enabled or disabled on managed systems.App Block Hook Status
Displays top three client versions with a single category for all other versions.Client Versions
Displays top three content versions with a single category for all other versions.Content Versions
Displays where Firewall protection is enabled or disabled on managed systems.Firewall Status
Displays where IPS protection is enabled or disabled on managed systems.Host IPS Status
Displays where Host IPS is installed and an update has occurred in the last week on
managed systems.
Service Status
Displays the number of Application Blocking client rules created over time.Count of AB Client rules
Displays the number of Firewall client rules created over time.Count of FW Client Rules
Managing Your Protection
Management of information
15McAfee Host Intrusion Prevention 7.0 Product Guide for use with ePolicy Orchestrator 4.0
Comentarios a estos manuales