6 Replies Latest reply: Aug 20, 2013 1:00 PM by lsouzasclara RSS

    HIPS 8.0

    lsouzasclara

      Hello,

       

      I´m starting to use HIPS.  I would like to know how to use? Best Practices?

       

      Can Anybody help me?

       

      Leonardo Souza

       

      Message was edited by: lsouzasclara on 8/14/13 3:41:54 PM BRT
        • 1. Re: HIPS 8.0
          Kary Tankink

          HIPS 8.0 Best Practices:

          Page 11 of:

           

          PD22891 - Host Intrusion Prevention 8.0 Installation Guide

          https://kc.mcafee.com/corporate/index?page=content&id=PD22891

          • 2. Re: HIPS 8.0
            lsouzasclara

            Hello Kary,

             

            Thanks for your hwlp.  I have another question.

             

            How can i enable the HIPS (Firewall, IPS andGeneral) logs?

             

            Thanks,

             

            Leonardo.

            • 3. Re: HIPS 8.0
              Kary Tankink

              In the HIPS ClientUI (mcafeefire.exe), the Activity Log tab contains most of the HIPS logs you'll need (specifically the Firewall traffic logs).  HIPS IPS signature violations events are sent to the ePO server console for review (MENU, REPORTING, Host IPS 8.0, Events).

              • 4. Re: HIPS 8.0
                lsouzasclara

                Kery,

                 

                Thank you for help again.  This is my firt time working with HIPS.

                 

                Regards,

                 

                Leonardo

                • 5. Re: HIPS 8.0
                  lsouzasclara

                  Kery,

                   

                  One More doubt.  I da four events,, but is doesn't show in (MENU, REPORTING, Host IPS 8.0, Events).

                   

                  What do I do?  Which Options I have to set?

                   

                  In General Setting I set Show tray icon and  nothing else.

                   

                  In Advanced Options nothing set.

                   

                  In Trobleshooting I set:

                  Firewall loggiond - Information

                  Activelog size                                                  - 2K

                  IPS logging: Information Log security violations too

                  Enable IPS engines all options.

                   

                  Can you help again?

                   

                  Regards,

                   

                  Leonardo

                  • 6. Re: HIPS 8.0
                    lsouzasclara

                    Re: HIPS 8.0

                    Kery,

                     

                    One More doubt. I da four events,, but is doesn't show in (MENU, REPORTING, Host IPS 8.0, Events).

                     

                    What do I do? Which Options I have to set?

                     

                    In General Setting I set Show tray icon and nothing else.

                     

                    In Advanced Options nothing set.

                     

                    In Trobleshooting I set:

                    Firewall loggiond - Information

                    Activelog size - 2K

                    IPS logging: Information Log security violations too

                    Enable IPS engines all options.

                     

                    Can you help again?

                     

                    Regards,

                     

                    Leonardo