
exception under Creating exception rules, for creating a trusted application under Creating
and editing Trusted Application rules.
Managing IPS client rules
Use this task to analyze IPS client rules created automatically when clients are in adaptive mode,
or manually on the client provided the Client UI policy option to allow manual creation of client
rules is enabled.
NOTE:
Access to IPS Client Rules on the Host IPS tab under Reporting requires additional permissions
other than that for Host Intrusion Prevention IPS, including view permissions for Event Log,
Systems, and System Tree access.
You can sort, filter, and aggregate the list of rules to find specific exceptions and see their
details. You can then promote some or all of the client exception rules to a particular IPS Rules
policy to reduce false positives for a particular system environment.
Use the aggregation feature to combine exceptions that have the same attributes, so that only
one aggregated exception appears, while keeping track of the number of times the exceptions
occur. This allows for easily finding IPS protection trouble spots on clients.
Task
For option definitions, click ? on the page displaying the options.
1 Go to Reporting | Host IPS | IPS Client Rules.
Figure 15: IPS Client Rules
2 Select the group in the System Tree for which you want to display client rules.
3 Determine how you want to view the list of client exceptions:
Do this...To...
Click the column header.Sort by a column
From the Filter menu select This Group Only or This
Group and All Su/jointfilesconvert/382709/bgroups.
Filter for groups
Configuring IPS Policies
Working with IPS Rules policies
43McAfee Host Intrusion Prevention 7.0 Product Guide for use with ePolicy Orchestrator 4.0
Comentarios a estos manuales