
• Apply the new policy to a set of computers and monitor the results.
• Repeat this process with each production group type.
Automatic tuning
Automatic tuning removes the need to constantly monitor all events and activities for all users.
• Apply adaptive mode for IPS, Firewall, and Application Blocking policies, or apply learn mode
for Firewall and Application Blocking policies.
• In adaptive mode, IPS events are not triggered and activity is not blocked, except for
malicious exploits. Client rules are created automatically to allow legitimate activity.
• In learn mode, the user receives an alert message and must indicate whether to allow or
block an activity. As a result, client rules are created.
• Review the lists of client rules.
• Promote appropriate client rules to administrative policy rules.
• After a few weeks turn off the adaptive or learn mode.
• Monitor the test group for a few days to be sure the policy settings are appropriate and offer
the desired protection.
• Repeat this process with each production group type.
Where to find policies
ePolicy Orchestrator provides two locations to view and manage Host Intrusion Prevention
policies:
• Systems | System Tree | Policies tab of a selected group in the System Tree
• Systems | Policy Catalog
Policies tab
Use the Policies tab to view the policies of a particular feature of the product, view details of
the policy, view inheritence information, edit policy assignment, and edit custom policies or
create a new policy relating to a selected group or system.
Policy Catalog
Use the Policy Catalog to create policies, view and edit policy information, view where a policy
is assigned, view the settings and owner of a policy, and view assignments where policy
enforcement is disabled.
Do this...To...
Click New Policy, name it, and edit the settings.
Create a policy
Click Edit (only available for My Default or custom policies).
Edit a policy
Click View (only available for McAfee Default or preconfigured policies).
View a policy
Click Rename and change the name of the policy (not available for default
or preconfigured policies).
Rename a policy
Click Duplicate, change the name of the policy, and edit the settings.
Duplicate a policy
Managing Your Protection
Management of policies
17McAfee Host Intrusion Prevention 7.0 Product Guide for use with ePolicy Orchestrator 4.0
Comentarios a estos manuales