H3C Technologies H3C SecCenter IPS Manager User Manual

Page 68

Advertising
background image

62

Table 61 Query options on the rule management page of an attack protection policy

Option Description

Event

Type or select an event to display the rule by the event name.
To select an event, follow the steps:

1.

Click the

icon to bring up the page, where you can locate a rule by its ID

(see

Figure 61

).

2.

Click the ID of a rule to display the rule name in the Event filed.

Event Type

Select an event type to display rules of the selected type.

Severity

Select a severity level to display the rules at the selected severity level.

Status

Select a rule state to display rules in the selected state.

Action

Select an action to display rules configured with the selected action.

Default

Select an option to display the modified or default rules.

Table 62 Fields of the attack protection rule list

Field Description

ID

ID of the rule

Name

Name of the protection rule

Type

Type of the rule

Severity

Severity of the rule

Status

Application status of the rule

Action

Action configured for the attack protection rule, which can be Block, Block+Notify,
Block+Notify+Packet Trace, Permit, Permit+Notify, or Permit+Notify+Packet

Trace.
The system will take the action if the rule is matched.

Default

Shows whether the rule is a default one or a modified one

Operation

Click the

icon of a rule to enter the rule modification page, where you can

change the application status and action of the rule, as shown in

Figure 62

. You

can also select a rule from the rule list (see

Figure 60

), and click Modify.

Click the

icon of a rule to view the details of the rule.

Advertising