    McAfee Host Intrusion Prevention Firewall - Connection-Aware Groups


      Hi, We are looking at using the CAG's within our environment and I have been testing these for awhile now.  I have a great understanding on how the work and how to configure them for our environment.  I really like them as it appears to help with management of the firewall rules.  I am wondering if others are using them and how you have them set up with in your organization?


      My thought is to set rules that are required regardless of connection or location.  Then have a CAG based on network adapter and a set of matches which once matched would allow anything to our trusted WAN.