
Policy enforcement
Not all Host Intrusion Prevention 8.0 policies are available for the Solaris client. In brief, Host
Intrusion Prevention protects the host server from harmful attacks but does not offer firewall
protection. The valid policies are listed here.
Available optionsPolicy
HIP 8.0 GENERAL:
None except administrator or time-based password to allow use of
the troubleshooting tool.
Client UI
NoneTrusted Networks
All except Mark trusted for Firewall.Trusted Applications
HIP 8.0 IPS:
IPS Options • Enable host IPS
• Enable adaptive mode
• Retain existing client Rules
AllIPS Protection
IPS Rules • Exception Rules
• Signatures (default and custom HIPS rules only)
NOTE: NIPS signatures and Application Protection Rules are not
available.
AllIPS Events
AllIPS Client Rules
HIP 8.0 FIREWALL:
NoneFirewall Options
NoneFirewall Rules
NoneFirewall DNS Blocking
NOTE: The client supports both global and local zones. Installation is done only in the global
zone.
Solaris Zone support
The client supports both global and local zone protection but is always installed in the global
zone. Restricting protection to particular zones is done by editing IPS Rules policy signatures,
where you add a zone section and include the name of the zone as a value.
For example, if you have a zone named "app_zone" whose root is /zones/app, the signature
rule would apply only to the file in the zone "app_zone" and not in the global zone. Note that
in this release, web server protection cannot be restricted to a particular zone. The code for
this rule would contain:
Rule {
...
file { Include "/tmp/test.log" }
zone { Include "app_zone" }
... }
Installing the Solaris Client
Solaris client details
McAfee Host Intrusion Prevention 8.0 Installation Guide40
Comentarios a estos manuales