18.07.2013 Views

Network Security Platform 7.0 IPS Administration Guide - McAfee

Network Security Platform 7.0 IPS Administration Guide - McAfee

Network Security Platform 7.0 IPS Administration Guide - McAfee

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

在规则集中配置智能阻止<br />

在“Rule Sets(规则集)”选项卡中,您可以按如下方式配置“智能阻止”:<br />

任务<br />

1 在“Manager”中,选择“<strong>IPS</strong> Settings(<strong>IPS</strong> 设置)” | “<strong>IPS</strong> & Recon(<strong>IPS</strong> 和侦测)” | “Rule Sets(规则集)”。<br />

2 要添加新规则集,请单击“New(新建)”。输入该规则集的“Name(名称)”和“Description(描述)”(可选)。<br />

3 要启用智能阻止,请选中“Enable SmartBlocking for <strong>McAfee</strong> Recommended for SmartBlocking (RFSB) attacks in<br />

this Rule Set(在此规则集中对 <strong>McAfee</strong> 建议智能阻止(RFSB)的攻击启用智能阻止)”。<br />

随即将显示三个阻止类别:“Exploit(利用漏洞)”、“Reconnaissance(侦测)”和“Policy Violation(违反策略)”。<br />

图 3-38 “Adding a rule set(添加规则集)”‑“SmartBlocking(智能阻止)”选项<br />

4 请至少选择以上其中一个类别,否则,会弹出一条错误消息,告知您至少要选择一个类别。<br />

默认情况下,内置的规则集“Default Inline <strong>IPS</strong>(默认串联 <strong>IPS</strong>)”处于启用状态,这会对“Exploit(利用漏洞)”攻击类别<br />

进行“智能阻止”。<br />

5 要添加规则,请选择“Rules(规则)”选项卡,然后选择“Insert(插入)”。<br />

6 在规则内容中,选择“Configure(配置)”。<br />

如何管理 <strong>IPS</strong> 设置<br />

如何配置和管理策略 3<br />

<strong>McAfee</strong> ® <strong>Network</strong> <strong>Security</strong> <strong>Platform</strong> <strong>7.0</strong> <strong>IPS</strong> 管理手册 65

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!