18.07.2013 Views

Network Security Platform 7.0 IPS Administration Guide - McAfee

Network Security Platform 7.0 IPS Administration Guide - McAfee

Network Security Platform 7.0 IPS Administration Guide - McAfee

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

任务<br />

1 在 Manager 中,选择“<strong>IPS</strong> Settings(<strong>IPS</strong> 设置)” | “Default Protection Options(默认保护选项)” | “IP Reputation<br />

(IP 信誉)”。<br />

2 在“IP Reputation(IP 信誉)”部分中,选择“Use IP Reputation to augment SmartBlocking?(是否使用 IP 信誉来增<br />

强智能阻止?)”选项,以增强对高风险主机攻击的阻止能力。<br />

图 5-128 “IP Reputation(IP 信誉)”对话框<br />

3 在“Protocols(协议)”部分中,可以选择从左侧的“Queried(已查询)”框中排除协议,以将排除的协议填充到右侧的<br />

“Whitelisted(白名单)”框中。<br />

这有助于优化查找性能。<br />

图 5-129 “Protocols(协议)”选项<br />

4 选择“Whitelist All Internal IP Addresses?(是否将所有内部 IP 地址列入白名单?)”以排除主机/网络,进而优化查找<br />

过程。<br />

图 5-130 “Whitelisted Hosts(白名单主机)”/“Whitelisted <strong>Network</strong>s(白名单网络)”选项<br />

如何管理 <strong>IPS</strong> 设置<br />

默认保护选项 3<br />

5 从“Participation(参与)”页选择“Inherit CIDR Exclusion list(继承 CIDR 排除列表)”,以直接从“Integration(集成)”<br />

| “Global Threat Intelligence” | “Participation(参与)”页添加排除列表。<br />

<strong>McAfee</strong> ® <strong>Network</strong> <strong>Security</strong> <strong>Platform</strong> <strong>7.0</strong> <strong>IPS</strong> 管理手册 169

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!