18.07.2013 Views

Network Security Platform 7.0 IPS Administration Guide - McAfee

Network Security Platform 7.0 IPS Administration Guide - McAfee

Network Security Platform 7.0 IPS Administration Guide - McAfee

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

3<br />

如何管理 <strong>IPS</strong> 设置<br />

防火墙策略<br />

• Local user 0 (local0)(本地用户 0 (local0))<br />

• Local user 1 (local1)(本地用户 1 (local1))<br />

• Local user 2 (local2)(本地用户 2 (local2))<br />

• Local user 3 (local3)(本地用户 3 (local3))<br />

• Local user 4 (local4)(本地用户 4 (local4))<br />

• Local user 5 (local5)(本地用户 5 (local5))<br />

• Local user 6 (local6)(本地用户 6 (local6))<br />

• Local user 7 (local7)(本地用户 7 (local7))<br />

7 指定要转发的防火墙警报的“Severity(严重性)”。选项包括:<br />

• Emergency(紧急):系统不可用<br />

• Alert(警报):必须立即采取措施<br />

• Critical(非常严重):非常严重的情况<br />

• Error(错误):错误情况<br />

• Warning(警告):警告情况<br />

• Notice(注意):普通但重要的情况<br />

• Informational(信息):信息性消息<br />

• Debug(调试):调试级消息<br />

8 单击“Test Connection(测试连接)”以检查 Manager 是否能将 syslog 发送到 syslog 服务器。<br />

检查 syslog 服务器,以确定其是否接收到了 Manager 发送的测试消息。若没有,请检查您所提供的 syslog 服务器<br />

名称或 IP 地址。通过 Manager 服务器对 syslog 服务器进行 Ping 操作,以查看 Manager 是否能到达 syslog 服务<br />

器。对于“防火墙访问规则(Firewall Access Rules)”,您可以将 M 系列 Sensor 配置为向 syslog 服务器直接发送消<br />

息。在这种情况下,请通过 Sensor 的 CLI 对 syslog 服务器执行 Ping 操作。此选项在防火墙“Logging(日志记录)”<br />

页面“(<strong>IPS</strong> Settings(<strong>IPS</strong> 设置)” | “Sensor_Name(Sensor 名称)” | “Firewall(防火墙)” | “Firewall Logging(防火墙<br />

日志记录))”上可用。<br />

166 <strong>McAfee</strong> ® <strong>Network</strong> <strong>Security</strong> <strong>Platform</strong> <strong>7.0</strong> <strong>IPS</strong> 管理手册

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!