Specifications
Match Selected − The currently applied VLAN is compared against one or more
VLANs selected from the list.
•
Exclude Selected − The currently applied VLAN is not one of the VLANs selected
from the list.
•
Day and Time Ranges
This tab lets you select one or more of your previously defined intervals, covering specific
days and times, to determine whether or not to apply an action.
Specify Action to take...
This area defines the actions to be taken when the event matches the above criteria set by a rule. It allows
taking a specific action on a port, MAC address, or IP address or taking a Custom Action (launching a
program to be run).
Action
Use this drop−down list to select a response to the threat: None, Disable Port, Apply Policy, or
Apply PVID.
Apply Policy
Use the Policy drop−down list to select a policy to be applied on the device. The available
policies are listed in the Policies tab. You must also specify whether to apply the policy to the
MAC source, IP source or the port.
Notify Trusted Access Manager. Select this checkbox if you want to configure ASM to
notify Trusted Access Manager when it quarantines a MAC address. Upon notification,
Trusted Access Manager automatically creates a MAC override and enforces the override to
all Trusted Access Gateways, effectively preventing the quarantined end−system from
accessing the network from any other location. When Trusted Access Manager creates the
override, it configures the policy passed by ASM as the Accept policy, and does not perform
a scan. If ASM reverses the quarantine, it notifies Trusted Access Manager, and the MAC
override is automatically deleted and removed from the gateways. You can view ASM
overrides in the Trusted Access Manager MAC Overrides tab.
Automated Security Manager Help
Specify Action to take... 159










