McAfee® Host Intrusion Prevention 6.1 Product Guide

Maintenance

 

Policy maintenance and tasks

8

Policy maintenance and tasks

ePolicy Orchestrator provides two locations on the console tree to view and manage Host Intrusion Prevention policies and tasks:

„Policies tab of a selected node in the console tree

„Policy Catalog page.

Policies tab

Use the Policies tab to view, modify, or create the policy information relating to a selected node. For details, see:

„IPS Policies on page 33

„Firewall Policies on page 68

„Application Blocking Policies on page 94

„General Policies on page 103.

Policy inheritance and assignment

The Policies tab enables you to lock or unlock policy inheritance, view and reset broken inheritance, and copy policy assignments from one node to another.

To lock the assignment of a custom policy:

1In the console tree, select a group or computer and click the Policies tab.

2Expand a Host Intrusion Prevention feature to display the policies assigned to the node.

3Click Edit for a custom policy.

4Select Lock, and then click Apply.

Only administrators can lock a named policy.

To view and reset broken inheritance below a specific node:

1In the console tree, select a group or computer and click the Policies tab.

2Expand a Host Intrusion Prevention feature to display the policies assigned to the node.

Figure 8-1 Policy inheritance

117

Page 117
Image 117
McAfee 6.1 manual Policy maintenance and tasks, Policies tab, Policy inheritance and assignment