McAfee FIREWALL 2.1-GETTING STARTED Przewodnik Instalacji

Przeglądaj online lub pobierz Przewodnik Instalacji dla Zapory sprzętowe McAfee FIREWALL 2.1-GETTING STARTED. McAfee FIREWALL 2.1-GETTING STARTED Installation guide Instrukcja obsługi

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 166
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów

Podsumowanie treści

Strona 1 - Firewall Roles 5.7

McAfee NGFW Installation Guidefor IPS and Layer 2 Firewall Roles 5.7NGFW Engine in the IPS and Layer 2 Firewall Roles

Strona 2 - Legal Information

10Chapter 1 Using SMC DocumentationHow to Use This GuideThe McAfee NGFW Installation Guide for IPS and Layer 2 Firewall Roles is intended for adminis

Strona 3 - TABLE OF CONTENTS

100Chapter 11 Installing the Engine on Other PlatformsStarting the InstallationBefore you start installing the engines, make sure you have the initia

Strona 4 - INSTALLING ENGINES

101Installing the Engine on a Virtualization PlatformInstalling the Engine on a Virtualization PlatformThe IPS or Layer 2 Firewall engine can be insta

Strona 5

102Chapter 11 Installing the Engine on Other PlatformsConfiguring the Engine Automatically with a USB StickThe automatic configuration is primarily i

Strona 6 - Table of Contents

103Configuring the Engine in the Engine Configuration WizardConfiguring the Engine in the Engine Configuration WizardIf you have stored the configurat

Strona 7 - INTRODUCTION

104Chapter 11 Installing the Engine on Other PlatformsConfiguring the Operating System Settings To set the keyboard layout1. Highlight the entry fie

Strona 8

105Configuring the Engine in the Engine Configuration WizardConfiguring the Network InterfacesThe Engine Configuration Wizard can automatically detect

Strona 9 - USING SMC DOCUMENTATION

106Chapter 11 Installing the Engine on Other PlatformsMapping the Physical Interfaces to Interface IDs To map the Physical Interfaces to Interface I

Strona 10

107Configuring the Engine in the Engine Configuration WizardContacting the Management ServerThe Prepare for Management Contact page opens. If the init

Strona 11 - Documentation Available

108Chapter 11 Installing the Engine on Other Platforms• If you see a “connection refused” error message, ensure that the one-time password is correct

Strona 12

109Installing the Engine in Expert ModePartitioning the Hard Disk ManuallyTypically, you need five partitions for the IPS or Layer 2 Firewall as expla

Strona 13 - INSTALLATION

11Documentation AvailableDocumentation AvailableSMC documentation is divided into two main categories: Product Documentation and Support Documentation

Strona 14

110Chapter 11 Installing the Engine on Other PlatformsAllocating PartitionsAfter partitioning the hard disk, the partitions are allocated for the eng

Strona 15 - PLANNING THE INSTALLATION

111UPGRADINGIn this section:Upgrading - 113

Strona 17 - Example Network Scenario

113CHAPTER 12UPGRADINGThis chapter explains how to upgrade your IPS engines, Layer 2 Firewalls, and Master Engines. When there is a new version of the

Strona 18

114Chapter 12 UpgradingGetting Started With UpgradingHow Engine Upgrades WorkThe primary way to upgrade engines is a remote upgrade through the Manag

Strona 19

115Getting Started With UpgradingTo check the current engine software version, select the engine in the System Status view. The engine version is disp

Strona 20 - Network TAPs

116Chapter 12 Upgrading7. Compare the displayed output to the checksum on the web site. To prepare a downloaded .zip file for a remote upgrade1. Log

Strona 21

117Upgrading or Generating LicensesUpgrading or Generating LicensesWhen you installed the engine software for the first time, you installed licenses t

Strona 22

118Chapter 12 Upgrading5. Select the location at which to save the license file in the dialog that opens. You areprompted to request a license upgrad

Strona 23 - INSTALLING LICENSES

119Upgrading Engines RemotelyUpgrading Engines RemotelyYou can upgrade the engines through the Management Server by importing the upgrade package manu

Strona 24

12Chapter 1 Using SMC DocumentationSupport DocumentationThe McAfee support documentation provides additional and late-breaking technical information.

Strona 25 - Generating New Licenses

120Chapter 12 UpgradingUpgrading Legacy IPS EnginesPrior to version 5.4, IPS engines consisted either of separate Sensor and Analyzer engines, or com

Strona 26

121Upgrading Legacy IPS Engines6. Make sure None is selected for the Analyzer.7. Click OK. The conversion begins.8. Refresh the policy of the upgraded

Strona 27 - CONFIGURING NAT ADDRESSES

122Chapter 12 UpgradingUpgrading Engines LocallyIt is also possible to upgrade the engines on the engine command line as described in this section. U

Strona 28

123Upgrading Engines LocallyUpgrading From a .zip FileFollow the instructions below if you want to use a .zip file to upgrade the engine software loca

Strona 29 - Defining Locations

124Chapter 12 Upgrading

Strona 30

125APPENDICESIn this section:Command Line Tools - 127Default Communication Ports - 149Example Network Scenario - 157Index - 163

Strona 32

127APPENDIX ACOMMAND LINE TOOLSThis appendix describes the command line tools for McAfee Security Management Center and the NGFW engines.The following

Strona 33 - DEFINING IPS ENGINES

128Appendix A Command Line ToolsSecurity Management Center CommandsSecurity Management Center commands include commands for the Management Server, Lo

Strona 34

129Security Management Center CommandssgArchiveExport(continued)Host specifies the address of the Management Server. If the parameter is not defined,

Strona 35

13PREPARING FORINSTALLATIONIn this section:Planning the Installation - 15Installing Licenses - 23Configuring NAT Addresses - 27

Strona 36

130Appendix A Command Line ToolssgBackupLogSrv[pwd=<password>][path=<destpath>][nodiskcheck][comment=<comment>][nofsstorage][-h | -

Strona 37

131Security Management Center CommandssgCertifyLogSrv[host=<Management Server Address[\Domain]>]Contacts the Management Server and creates a new

Strona 38

132Appendix A Command Line ToolssgChangeMgtIPOnMgtSrv <IP address>Changes the Management Server’s IP address in the local configuration to the

Strona 39

133Security Management Center CommandssgHA [host=<Management Server Address[\Domain]>][login=<login name>][pass=<password>][master=&

Strona 40

134Appendix A Command Line ToolssgImportExportUser[host=<Management Server Address[\Domain]>][login=<login name>][pass=<password>]a

Strona 41

135Security Management Center CommandssgOnlineReplication[login=<login name>][pass=<password>][active-server=<name of active Management

Strona 42

136Appendix A Command Line ToolssgRestoreAuthBackup[-pwd=<password>][-backup=<backup file name>][-nodiskcheck][-h|-help]Restores the Auth

Strona 43 - DEFINING LAYER 2 FIREWALLS

137Security Management Center CommandssgStartMgtSrv Starts the Management Server and its database. sgStartWebPortalSrv Starts the Web Portal Server.sg

Strona 44

138Appendix A Command Line ToolssgTextBrowser[host=<Management Server address[\Domain]>][login=<login name>][pass=<password>][forma

Strona 45

139NGFW Engine CommandsNGFW Engine CommandsThe commands in the following two tables can be run on the command line on Firewall, Layer 2 Firewall, IPS

Strona 47

140Appendix A Command Line Toolssg-blacklist show [-v] [-f FILENAME] |add [[-i FILENAME] | [src IP_ADDRESS/MASK] [src6 IPv6_ADDRESS/PREFIX][dst IP_AD

Strona 48

141NGFW Engine Commandssg-blacklist (continued)Firewall, Layer 2 Firewall, IPSAdd/Del Parameters:Enter at least one parameter. The default value is us

Strona 49

142Appendix A Command Line Toolssg-clear-allFirewall, Layer 2 Firewall, IPSNote! Use this only if you want to clear all configuration information fro

Strona 50

143NGFW Engine Commandssg-dynamic-routing [start][stop][restart][force-reload][backup <file>][restore <file>][sample-config][route-table][

Strona 51

144Appendix A Command Line Toolssg-raid[-status] [-add] [-re-add] [-force] [-help]Firewall, Layer 2 Firewall, IPSConfigures a new hard drive. This co

Strona 52

145NGFW Engine Commandssg-toggle-activeSHA1 SIZE |--force [--debug]Firewall, Layer 2 Firewall, IPSSwitches the engine between the active and the inact

Strona 53 - VIRTUAL IPS ENGINES

146Appendix A Command Line ToolsThe table below lists some general Linux operating system commands that may be useful in running your engines. Some c

Strona 54

147Server Pool Monitoring Agent CommandsServer Pool Monitoring Agent CommandsYou can test and monitor the Server Pool Monitoring Agents on the command

Strona 55

148Appendix A Command Line Toolssgmon [status|info|proto][-p port] [-t timeout] [-a id]hostSends a UDP query to the specified host and waits for a re

Strona 56

149APPENDIX BDEFAULT COMMUNICATION PORTSThis chapter lists the default ports used in connections between SMC components and the default ports SMC comp

Strona 57

15CHAPTER 2PLANNING THE INSTALLATIONThis chapter provides important information to take into account before the installation can begin. The chapter al

Strona 58 - Options Explanation

150Appendix B Default Communication PortsSecurity Management Center PortsThe illustrations below present an overview to the most important default po

Strona 59

151Security Management Center PortsThe table below lists all default ports SMC uses internally and with external components. Many of these ports can b

Strona 60

152Appendix B Default Communication PortsManagement Server3021/TCPLog Server, Web Portal ServerSystem communications certificate request/renewal.SG L

Strona 61 - Option Explanation

153Security Engine PortsSecurity Engine PortsThe illustrations below present an overview to the most important default ports used in communications be

Strona 62

154Appendix B Default Communication PortsThe table below lists all default ports the Security Engines use internally and with external components. Ma

Strona 63

155Security Engine PortsFirewall, Layer 2 Firewall, IPS, Master Engine4987/TCPManagement ServerManagement Server commands and policy upload.SG Command

Strona 64

156Appendix B Default Communication PortsRPC server111/UDP, 111/TCPFirewall, Master EngineRPC number resolve.SUNRPC (UDP), Sun RPC (TCP)Server Pool M

Strona 65

157APPENDIX CEXAMPLE NETWORK SCENARIOTo give you a better understanding of how McAfee IPS fits into a network, this section outlines a network with IP

Strona 66

158Appendix C Example Network ScenarioOverview of the Example NetworkTwo example IPS installations are described in this guide: • an IPS cluster in t

Strona 67 - VIRTUAL LAYER 2 FIREWALLS

159Example Headquarters Intranet NetworkExample Headquarters Intranet NetworkIllustration C.2 Example Headquarters Intranet NetworkHQ IPS ClusterIn t

Strona 68

16Chapter 2 Planning the InstallationIntroduction to McAfee IPS and Layer 2 FirewallA McAfee IPS or Layer 2 Firewall system consists of the McAfee Se

Strona 69

160Appendix C Example Network ScenarioExample Headquarters Management NetworkIllustration C.3 Example Headquarters Management NetworkHQ FirewallThe

Strona 70

161Example Headquarters DMZ NetworkExample Headquarters DMZ NetworkIllustration C.4 Example Headquarters DMZ NetworkDMZ IPSIn the example scenario, t

Strona 71

162Appendix C Example Network Scenario

Strona 72

163IndexINDEXAAdvanced Configuration and Power Interface (ACPI), 98analyzers, removing after upgrade, 121Automatic Power Management (APM), 98BBIOS set

Strona 73

164Index IPS installation modes, 16IPS policiescustomized high-security inspection IPS policy, 92default IPS policy, 92IPS template policies, 92Llaye

Strona 74

165Indexreset interfaces, 40, 49transferring initial configuration to engines, 87typographical conventions, 10Uupgrading, 113–123engine locally, 122en

Strona 75

Copyright © 2014 McAfee, Inc. Do not copy without permission.McAfee and the McAfee logo are trademarks or registered trademarks of McAfee, Inc. or its

Strona 76

17Example Network ScenarioThe main features of McAfee IPS and Layer 2 Firewall include:• Multiple detection methods: misuse detection uses fingerprint

Strona 77

18Chapter 2 Planning the InstallationOverview to the Installation Procedure1. Check the surrounding network environment as explained in Capture Inter

Strona 78

19Important to Know Before InstallationImportant to Know Before InstallationBefore you start the installation, you need to carefully plan the site tha

Strona 79

2Legal InformationThe use of the products described in these materials is subject to the then current end-user license agreement, which can be found a

Strona 80

20Chapter 2 Planning the InstallationSwitch SPAN PortsA Switched Port Analyzer (SPAN) port is used for capturing network traffic to a defined port on

Strona 81

21Important to Know Before InstallationIllustration 2.2 Correct Cable Types for Single Layer 2 FirewallsFor more information on cabling for IPS engin

Strona 82

22Chapter 2 Planning the Installation

Strona 83 - CHAPTER 9

23CHAPTER 3INSTALLING LICENSESThis chapter instructs how to generate and install licenses for IPS engines, Layer 2 Firewalls, and Master Engines.The f

Strona 84

24Chapter 3 Installing LicensesGetting Started with IPS and Layer 2 Firewall LicensesEach IPS engine, Layer 2 Firewall, and Master Engine must have i

Strona 85

25Generating New LicensesConfiguration OverviewThe following steps are needed for installing licenses for IPS engines, Layer 2 Firewall engines, and M

Strona 86

26Chapter 3 Installing LicensesInstalling LicensesTo install licenses, the license files must be available to the computer you use to run the Managem

Strona 87

27CHAPTER 4CONFIGURING NAT ADDRESSESThis chapter contains the steps needed to configure Locations and contact addresses when a NAT (network address tr

Strona 88

28Chapter 4 Configuring NAT AddressesGetting Started with NAT AddressesIf there is network address translation (NAT) between communicating SMC compon

Strona 89 - POLICIES

29Defining LocationsConfiguration OverviewTo add contact addresses, proceed as follows:1. Define Location element(s). See Defining Locations.2. Define

Strona 90

3Table of ContentsTABLE OF CONTENTSINTRODUCTIONCHAPTER 1Using SMC Documentation. . . . . . . . . . . . . . . . 9How to Use This Guide . . . . . . . .

Strona 91 - Configuring Routing

30Chapter 4 Configuring NAT AddressesAdding SMC Server Contact AddressesThe Management Server and the Log Server can have more than one contact addre

Strona 92

31CONFIGURING ENGINESIn this section:Defining IPS Engines - 33Defining Layer 2 Firewalls - 43Configuring Master Engines and Virtual IPS Engines - 53Co

Strona 94

33CHAPTER 5DEFINING IPS ENGINESThis chapter contains the steps needed to complete the IPS engine configuration that prepares the SMC for IPS engine in

Strona 95

34Chapter 5 Defining IPS EnginesGetting Started with Defining IPS EnginesThe IPS engine elements are a tool for configuring nearly all aspects of you

Strona 96

35Defining System Communication Interfaces for IPS EnginesDefining System Communication Interfaces for IPS EnginesEach IPS engine needs at least one i

Strona 97 - PLATFORMS

36Chapter 5 Defining IPS EnginesDefining IP Addresses To define an IP address for a single IPS1. Right-click a Physical Interface or a VLAN Interfac

Strona 98 - .iso image files

37Setting Interface Options for IPS EnginesSetting Interface Options for IPS EnginesInterface options allow you to select which interfaces are used fo

Strona 99

38Chapter 5 Defining IPS EnginesDefining Traffic Inspection Interfaces for IPS EnginesIPS engines pick up passing network traffic for inspection in r

Strona 100 - 2 and press Enter

39Defining Traffic Inspection Interfaces for IPS EnginesDefining Logical InterfacesA Logical Interface is used in the IPS policies and the traffic ins

Strona 101

4Table of ContentsCHAPTER 7Configuring Master Engines and Virtual IPS Engines . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 53Configura

Strona 102

40Chapter 5 Defining IPS EnginesDefining Reset InterfacesReset Interfaces can deliver TCP resets and ICMP “destination unreachable” messages to inter

Strona 103

41Defining Traffic Inspection Interfaces for IPS EnginesRepeat these steps to define any additional Capture Interfaces.Defining Inline InterfacesThe n

Strona 104

42Chapter 5 Defining IPS EnginesBypassing Traffic on OverloadBy default, inline IPS engines inspect all connections. If the traffic load is too high

Strona 105

43CHAPTER 6DEFINING LAYER 2 FIREWALLSThis chapter contains the steps needed to complete the Layer 2 Firewall engine configuration that prepares the SM

Strona 106

44Chapter 6 Defining Layer 2 FirewallsGetting Started with Defining Layer 2 FirewallsThe Layer 2 Firewall engine elements are a tool for configuring

Strona 107

45Defining System Communication Interfaces for Layer 2 Firewall EnginesDefining System Communication Interfaces for Layer 2 Firewall EnginesEach Layer

Strona 108

46Chapter 6 Defining Layer 2 FirewallsDefining IP Addresses To define an IP address for a Single Layer 2 Firewall1. Right-click a Physical Interface

Strona 109

47Setting Interface Options for Layer 2 Firewall EnginesSetting Interface Options for Layer 2 Firewall EnginesInterface options allow you to select wh

Strona 110

48Chapter 6 Defining Layer 2 FirewallsDefining Traffic Inspection Interfaces for Layer 2 Firewall EnginesLayer 2 Firewalls pick up passing network tr

Strona 111 - UPGRADING

49Defining Traffic Inspection Interfaces for Layer 2 Firewall Engines6. Click OK.Repeat these steps to define any additional Logical Interfaces.Defini

Strona 112

5Table of ContentsUPGRADINGCHAPTER 12Upgrading . . . . . . . . . . . . . . . . . . . . . . . . . . . . 113Getting Started With Upgrading . . . . . .

Strona 113

50Chapter 6 Defining Layer 2 FirewallsDefining Capture InterfacesCapture Interfaces listen to traffic that is not routed through the Layer 2 Firewall

Strona 114 - Chapter 12 Upgrading

51Finishing the Engine ConfigurationDefining Inline InterfacesThe number of Inline Interfaces you can have is limited by the license in use. One Inlin

Strona 115

52Chapter 6 Defining Layer 2 Firewalls

Strona 116

53CHAPTER 7CONFIGURING MASTER ENGINESAND VIRTUAL IPS ENGINESThis chapter contains the steps needed to complete the Master Engine and Virtual IPS engin

Strona 117

54Chapter 7 Configuring Master Engines and Virtual IPS EnginesConfiguration OverviewVirtual IPS engines are logically-separate Virtual Security Engin

Strona 118

55Adding a Master Engine ElementAdding a Master Engine ElementTo introduce a new Master Engine to the SMC, you must define a Master Engine element tha

Strona 119 - Upgrading Engines Remotely

56Chapter 7 Configuring Master Engines and Virtual IPS EnginesAdding Nodes to a Master EngineThe Master Engine properties have placeholders for two n

Strona 120

57Adding Physical Interfaces for Master EnginesAdding Physical Interfaces for Master EnginesMaster Engines can have two types of Physical Interfaces:

Strona 121 - YES to confirm

58Chapter 7 Configuring Master Engines and Virtual IPS Engines4. (Interface for hosted Virtual IPS engine communications only) Define the Physical In

Strona 122

59Adding Physical Interfaces for Master Engines5. Click OK. The Physical Interface is added to the interface list.6. Repeat from Step 2 to add any oth

Strona 124

60Chapter 7 Configuring Master Engines and Virtual IPS EnginesAdding VLAN Interfaces for Master EnginesVLANs divide a single physical network link in

Strona 125 - APPENDICES

61Adding VLAN Interfaces for Master Engines4. Click OK. The specified VLAN ID is added to the Physical Interface.Second VLAN ID(Optional, only if Phys

Strona 126

62Chapter 7 Configuring Master Engines and Virtual IPS Engines5. Repeat from Step 2 to add further VLANs on the same or other Physical Interfaces.Add

Strona 127 - COMMAND LINE TOOLS

63Setting Global Interface Options for Master EnginesSetting Global Interface Options for Master EnginesThe Interface Options dialog contains the sett

Strona 128

64Chapter 7 Configuring Master Engines and Virtual IPS Engines4. Click OK to close the Master Engine Properties. A Confirmation dialog opens. Click N

Strona 129 - Command Description

65Configuring Physical Interfaces for Virtual IPS EnginesConfiguring Physical Interfaces for Virtual IPS EnginesPhysical Interfaces for Virtual IPS en

Strona 130

66Chapter 7 Configuring Master Engines and Virtual IPS Engines4. If your configuration requires you to change the Logical Interface from Default_Eth,

Strona 131

67CHAPTER 8CONFIGURING MASTER ENGINESAND VIRTUAL LAYER 2 FIREWALLSThis chapter contains the steps needed to complete the Master Engine and Virtual Lay

Strona 132

68Chapter 8 Configuring Master Engines and Virtual Layer 2 FirewallsConfiguration OverviewVirtual Layer 2 Firewalls are logically-separate Virtual Se

Strona 133

69Adding a Master Engine ElementAdding a Master Engine ElementTo introduce a new Master Engine to the SMC, you must define a Master Engine element tha

Strona 134

7INTRODUCTIONIn this section:Using SMC Documentation - 9

Strona 135

70Chapter 8 Configuring Master Engines and Virtual Layer 2 FirewallsAdding Nodes to a Master EngineThe Master Engine properties have placeholders for

Strona 136

71Adding Physical Interfaces for Master EnginesAdding Physical Interfaces for Master EnginesMaster Engines can have two types of Physical Interfaces:

Strona 137

72Chapter 8 Configuring Master Engines and Virtual Layer 2 Firewalls4. (Interface for Hosted Virtual Layer 2 Firewall communications only) Define the

Strona 138

73Adding Physical Interfaces for Master Engines5. Click OK. The Physical Interface is added to the interface list.6. Repeat from Step 2 to add any oth

Strona 139 - NGFW Engine Commands

74Chapter 8 Configuring Master Engines and Virtual Layer 2 FirewallsAdding VLAN Interfaces for Master EnginesVLANs divide a single physical network l

Strona 140 - Description

75Adding VLAN Interfaces for Master Engines4. Click OK. The specified VLAN ID is added to the Physical Interface.Second VLAN ID(Optional, only if Phys

Strona 141

76Chapter 8 Configuring Master Engines and Virtual Layer 2 Firewalls5. Repeat from Step 2 to add further VLANs on the same or other Physical Interfac

Strona 142

77Setting Global Interface Options for Master EnginesSetting Global Interface Options for Master EnginesThe Interface Options dialog contains the sett

Strona 143

78Chapter 8 Configuring Master Engines and Virtual Layer 2 Firewalls4. Click OK to close the Master Engine Properties. A Confirmation dialog opens. C

Strona 144

79Configuring Physical Interfaces for Virtual Layer 2 FirewallsConfiguring Physical Interfaces for Virtual Layer 2 FirewallsPhysical Interfaces for Vi

Strona 146

80Chapter 8 Configuring Master Engines and Virtual Layer 2 FirewallsAdding VLAN Interfaces for Virtual Layer 2 FirewallsVLAN Interfaces can only be a

Strona 147

81Binding Engine Licenses to Correct ElementsBinding Engine Licenses to Correct ElementsLicenses are created based on the Management Server’s proof-of

Strona 148

82Chapter 8 Configuring Master Engines and Virtual Layer 2 Firewalls

Strona 149 - DEFAULT COMMUNICATION PORTS

83CHAPTER 9SAVING THE INITIAL CONFIGURATIONThis chapter explains how to save an IPS, Layer 2 Firewall, or Master Engine element configuration in the S

Strona 150

84Chapter 9 Saving the Initial ConfigurationConfiguration OverviewOnce you have configured the IPS, Layer 2 Firewall, or Master Engine elements in th

Strona 151

85Saving the Initial ConfigurationPreparing for Automatic Configuration To prepare for automatic configuration1. (Optional) Select Enable SSH Daemon

Strona 152

86Chapter 9 Saving the Initial ConfigurationPreparing for Configuration Using the Engine Configuration Wizard To prepare for configuration using the

Strona 153 - Security Engine Ports

87Transferring the Initial Configuration to the EnginesTransferring the Initial Configuration to the EnginesYou are now ready to install the engine(s)

Strona 154

88Chapter 9 Saving the Initial Configuration

Strona 155

89CHAPTER 10CONFIGURING ROUTING AND INSTALLING POLICIESAfter successfully installing the engines and establishing contact between the engine(s) and th

Strona 156

9CHAPTER 1USING SMC DOCUMENTATIONThis chapter describes how to use the McAfee NGFW Installation Guide for IPS and Layer 2 Firewall Roles and lists oth

Strona 157 - EXAMPLE NETWORK SCENARIO

90Chapter 10 Configuring Routing and Installing PoliciesConfiguring RoutingRouting is configured entirely through the Management Client. The routing

Strona 158

91Configuring RoutingAdding Next-Hop RoutersYou may need to define a default route in case the SMC (Management Servers and Log Servers) and other SMC

Strona 159 - Interface

92Chapter 10 Configuring Routing and Installing PoliciesInstalling the Initial PolicyTo be able to inspect traffic, the engines must have a policy in

Strona 160 - SMC Server Description

93Installing the Initial PolicyThe default policy elements are introduced when you import and activate a recent dynamic update package (for example, d

Strona 161

94Chapter 10 Configuring Routing and Installing Policies To install a ready-made policy1. Select Configuration→Configuration→Security Engine. The Se

Strona 162

95INSTALLING ENGINESIn this section:Installing the Engine on Other Platforms - 97

Strona 164

97CHAPTER 11INSTALLING THE ENGINE ON OTHER PLATFORMSThis chapter describes how to install IPS and Layer 2 Firewall engines on standard Intel or Intel-

Strona 165

98Chapter 11 Installing the Engine on Other PlatformsInstalling the Engine on Intel-Compatible PlatformsMcAfee NGFW appliances are delivered with pre

Strona 166

99Installing the Engine on Intel-Compatible PlatformsChecking File IntegrityBefore installing the IPS or Layer 2 Firewall engine from downloaded files

Komentarze do niniejszej Instrukcji

Brak uwag