18.07.2013 Views

Network Security Platform 7.0 IPS Administration Guide - McAfee

Network Security Platform 7.0 IPS Administration Guide - McAfee

Network Security Platform 7.0 IPS Administration Guide - McAfee

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

6 单击“Save(保存)”。<br />

弹出窗口显示需要将策略更改下载到 Sensor。<br />

7 在弹出窗口中单击“OK(确定)”,您将被重定向到“Configuration Update(配置更新)”页。<br />

有关详细信息,请参阅“更新一个 Sensor 的配置”。<br />

攻击过滤器分配<br />

您可以在域级别上分配攻击过滤器或将其分配给特定的 Sensor。<br />

要在域级别上分配攻击过滤器,请转至 “<strong>IPS</strong> Settings(<strong>IPS</strong> 设置)” | “Attack Filters(攻击过滤器)” | “Filter Assignments<br />

(过滤器分配)”。<br />

要在 Sensor 级别上分配攻击过滤器,请转至“<strong>IPS</strong> Settings(<strong>IPS</strong> 设置)” | “Sensor_Name(Sensor 名称)” | “<strong>IPS</strong><br />

Sensor” | “Protection Profile(保护配置文件)” | “Attack Filter Assignments(攻击过滤器分配)”。<br />

“Attack Filter Assignments(攻击过滤器分配)”页会显示两个选项卡:“Exploit(利用漏洞)”和“Reconnaissance(侦<br />

测)”。<br />

图 4-3 编辑攻击过滤器分配<br />

“Exploit(利用漏洞)”选项卡下的字段<br />

在 Sensor 级别配置 <strong>IPS</strong> 策略<br />

<strong>IPS</strong> Sensor 设置 4<br />

“Exploit(利用漏洞)”选项卡有两个子选项卡:“Inbound(入站)”/“Outbound(出站)”。这两个子选项卡显示相同的字段,<br />

但一个显示的是入侵攻击,另一个显示的是外发攻击。<br />

<strong>McAfee</strong> ® <strong>Network</strong> <strong>Security</strong> <strong>Platform</strong> <strong>7.0</strong> <strong>IPS</strong> 管理手册 239

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!