18.07.2013 Views

Network Security Platform 7.0 IPS Administration Guide - McAfee

Network Security Platform 7.0 IPS Administration Guide - McAfee

Network Security Platform 7.0 IPS Administration Guide - McAfee

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

步骤:<br />

a 转到“<strong>IPS</strong> Settings(<strong>IPS</strong> 设置)” | “Sensor_Name(Sensor 名称)” | “Interface‑x(接口 x)” | “<strong>IPS</strong> Interface(<strong>IPS</strong><br />

接口)” | “Protection Profile(保护配置文件)” | “HTTP Response Scanning(HTTP 响应扫描)”。<br />

图 5-30 “HTTP Response Scanning(HTTP 响应扫描)”设置<br />

b 在“Outbound Status(出站状态)”部分下面选择 1A‑1B,对出站流量启用 HTTP 响应检测。<br />

示例 2<br />

考虑相反的情况。如果来自您的网络外部的客户端计算机连接到内部 Web 服务器,则整个流(包括响应流量)会视<br />

为入站流。例如,为了防止外部客户端受到已遭破坏的内部 Web 服务器的侵扰,请对入站流量启用 HTTP 响应扫<br />

描。<br />

步骤:<br />

a 转到“<strong>IPS</strong> Settings(<strong>IPS</strong> 设置)” | “Sensor_Name(Sensor 名称)” | “Interface‑x(接口 x)” | “<strong>IPS</strong> Interface(<strong>IPS</strong><br />

接口)” | “Protection Profile(保护配置文件)” | “HTTP Response Scanning(HTTP 响应扫描)”。<br />

b 在“Inbound Status(入站状态)”下面选择 1A‑1B,对入站流量启用 HTTP 响应检测。<br />

示例 3<br />

在接口和子接口级别配置策略<br />

<strong>IPS</strong> Sensor 接口节点 5<br />

如果您希望在上述两种情况下为您的网络提供保护,则需对入站和出站流量均启用 HTTP 响应扫描。<br />

<strong>McAfee</strong> ® <strong>Network</strong> <strong>Security</strong> <strong>Platform</strong> <strong>7.0</strong> <strong>IPS</strong> 管理手册 323

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!