18.07.2013 Views

Network Security Platform 7.0 IPS Administration Guide - McAfee

Network Security Platform 7.0 IPS Administration Guide - McAfee

Network Security Platform 7.0 IPS Administration Guide - McAfee

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

以下含义和先决条件应用于在 Edit Alert Details(编辑警报详细信息)页中启用警报的情境下:<br />

拒绝服务<br />

自定义攻击响应的工作方式 7<br />

• Enable Alert(启用警报)表示将警报从 Sensor 或 <strong>Network</strong> Threat Behavior Analysis Appliance 发送到 Manager。<br />

• 在管理域级别,在 Alert Notification(警报通知)选项卡中启用“Email(电子邮件)”、“Script(脚本)”、“Pager(寻呼<br />

机)”、SNMP 和 Syslog(“Admin_Domain_Name(管理域名称)” | “<strong>IPS</strong> Settings(<strong>IPS</strong> 设置)” | “Alert Notification(警<br />

报通知)”或“Admin_Domain_Name(管理域名称)” | “NTBA Settings(NTBA 设置)” | “Alert Notification(警报通<br />

知)”)是转发这些通知的先决条件。<br />

• 特定于电子邮件转发的另一个先决条件是在 Sensor 级别配置电子邮件服务器设置(“Root_Admin_Domain(根管理<br />

域)” | “Manager” | “Misc(其他)” | “E‑mail Server(电子邮件服务器)”)。<br />

利用漏洞攻击、侦测攻击、NTBA 攻击和 DoS 阈值攻击的 Edit Attack Details(编辑攻击详细信息)页包含的选项与<br />

上图略有差异;但是本节描述的自定义规则同样适用于上述攻击。<br />

<strong>McAfee</strong> ® <strong>Network</strong> <strong>Security</strong> <strong>Platform</strong> <strong>7.0</strong> <strong>IPS</strong> 管理手册 399

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!