
The application rules list displays rules relevant to the client and provides summary and detailed
information for each rule.
Displays...This column...
The purpose of this rule.Description
Permits application to run. Blocks application from running.
Create
Permits application to hook other programs. Blocks application from hooking
other programs.
Hook
The file name and path of the application that this rule applies to.Application
Customizing Application Policy options
Use this task to customize Application Blocking options.
Task
1 Click the Application Policy tab.
2 Select or deselect an option as needed.
To do this...Select...
Enable application creation blocking. The Enable Learn Mode Application Creation
options is enabled.
Enable Application Creation
Blocking
Enable application hooking blocking.The Enable Learn Mode Application Hooking
options is enabled
Enable Application Hooking
Blocking
Enable learn mode for application creation, where the user is prompted to allow
or block application creation.
Enable Learn Mode
Application Creation
Enable learn mode for application hooking, where the user is prompted to allow
or block application hooking.
Enable Learn Mode
Application Hooking
About the Blocked Hosts tab
Use the Blocked Hosts tab to monitor a list of blocked
hosts
(IP addresses) that is automatically
created when Network IPS (NIPS) protection is enabled. If Create Client Rules is selected in
the IPS Options policy in the ePolicy Orchestrator console, you can add to and edit the list of
blocked hosts.
The blocked hosts list shows all hosts currently blocked by Host Intrusion Prevention. Each line
represents a single host. You can get more information on individual hosts by reading the
information in each column.
What it showsColumn
Source
• The IP address that Host Intrusion Prevention is blocking.
Blocked Reason
• An explanation of why Host Intrusion Prevention is blocking this address.
If Host Intrusion Prevention added this address to the list because of an attempted
attack on your system, this column describes the type of attack.If Host Intrusion
Prevention added this address because one of its firewall rules used the Treat rule
match as intrusion option, this column lists the name of the relevant firewall rule.If
you added this address manually, this column lists only the IP address that you blocked.
Working with Host Intrusion Prevention Clients
Overview of the Windows client
McAfee Host Intrusion Prevention 7.0 Product Guide for use with ePolicy Orchestrator 4.096
Kommentare zu diesen Handbüchern