Skip navigation
McAfee Secure sites help keep you safe from identity theft, credit card fraud, spyware, spam, viruses and online scams
489 Views 1 Reply Latest reply: Apr 16, 2013 1:25 PM by damageinc RSS
kenobe Apprentice 90 posts since
Mar 15, 2012
Currently Being Moderated

Apr 16, 2013 12:46 PM

Please wait...  and wait and wait

Please wait...

 

When reviewing my Threat Event Log I find an event and try to import that as an exception to my HIPS 8 IPS policy.  It literally takes 30 minutes to finish "Creating Exceptions".

Then, I go into the IPS RULES policy and verify the Exeption Rule.  I hit SAVE and wait at least 30 more minutes.

This is a fresh ePO 4.5 MR5 server with multiple CPUs and 64GB of memory (all virtual).  SQL is on the same box as the ePO server.

 

Why does it take so long to edit a single rule?  Granted, I have 26 pages of IPS rules but a beefy server should be able to handle this, right???

 

please wait.png

 

Message was edited by: kenobe on 4/16/13 12:45:42 PM CDT

 

Message was edited by: kenobe on 4/16/13 12:46:11 PM CDT
  • damageinc Apprentice 51 posts since
    Nov 22, 2011
    Currently Being Moderated
    1. Apr 16, 2013 1:25 PM (in response to kenobe)
    Re: Please wait... and wait and wait

    This has been a long standing issue for us.  IPS policies take a remarkably large amount of time to save, even with very clean policies and good tuning practices.  It seems that the amount of time it takes is directly related to the size of the EPOProductSettings table.  If you have Policy Auditor 6.0 installed, you can check the size of this table by using the "PA: Table Space Usage" query.

     

    You can do some things to reduce policy sizes, and that does actually seem to help.  For example, try to remove the Application Protection Rules from any non-McAfee Default IPS Rules policy.  You can also delete unused policies that are just taking up space.

     

    One other odd thing you can do is to change your server's power settings in the BIOS and in Windows.  If you turn everything onto "high performance" mode, it actually makes quite a bit of difference.  Good luck.

     

    -DamageInc

More Like This

  • Retrieving data ...

Bookmarked By (0)

Legend

  • Correct Answers - 5 points
  • Helpful Answers - 3 points