Setup guide
McAfee ePO
Advanced Suite Installer Product Guide
McAfee ePO
Advanced Suite Installer Page 35
IPS Protection
After all the required components for Host IPS are installed and communicating, you are ready to apply
protection, monitor events, and update policies and content as needed.
Similar to the default Enhanced Protection, this policy blocks High and Medium events and also logs Low
severity events. Only block Medium events after first logging and reviewing them to see if any
exceptions should be created.
• EASI - Block High and Medium events
Only High severity events are blocked; Medium and Low events are only logged.
• EASI - Block High events
Also a good starter policy but only logs High, Medium and Low severity events without any blocking.
• EASI - Initial monitoring (pre-blocking)
IPS Rules
These policies define the signatures, exceptions, and application protection rules to be used.
As virtual systems are often used for evaluations, assigning this policy facilitates testing by changing
VMWare-related signatures to a severity of Low.
• EASI - VMware exception policy
SiteAdvisor Enterprise 3.5
Authorize List (UBP)
The following policy ensures that sites specifically listed in the Authorize Policy are allowed even if listed
in the Prohibit Policy:
• EASI – Authorize Policy
Enable/Disable (UBP)
Applied to a group or subgroup, the Disable policy below can quickly deactivate SiteAdvisor on the client
systems. Assigning a different policy such as the McAfee Default or another policy to Enable will
reactivate SiteAdvisor Enterprise on those systems.
• EASI – Disable SAE Policy
General (UBP)
The following policy enables file download and email annotations rating:
• EASI – General