
Migrating Policies
You cannot use McAfee Host Intrusion Prevention version 6.1 or 7.0 policies with version 8.0
clients without first migrating version 6.1 or 7.0 policies to version 8.0 format. Host Intrusion
Prevention 8.0 provides an easy means to migrate policies with the ePolicy Orchestrator Host
IPS Policy Migration feature under Automation. This migration involves translating and
moving policies. After the policy is migrated it appears under the Policy Catalog's corresponding
Host IPS 8.0 product feature and category with [6.1] or [7.0] following the name of the policy.
All policies are translated and migrated to corresponding version 8.0 policies, except for the
following:
• Application Blocking Options policies are not migrated (these policies were removed in version
8.0).
• Application Blocking Rules policies are migrated into IPS Rules policies named Application
Hooking and Invocation Protection <name> [6.1 or 7.0] . After these policies are
migrated into IPS Rules policies, their Application Protection Rules list is blank, and the
Exceptions list contains exceptions for all default trusted applications set to "Trusted for
Application Hooking." To use this migrated policy you must also assign the My Default IPS
Rules policy in a multiple-policy instance setting, as it contains the latest application protection
list through content updates.
NOTE: Applications for which hooking is blocked in Application Blocking Rules policies are
not migrated and need to be manually added to the Application Protection Rules in the IPS
Rules policy after migration. Also, if you migrate a Trusted Applications policy with applications
marked "Trusted for application hooking" to version 8.0, you must create an exception for
that application in signature 6010 (Generic Application Hooking Protection) in a Host IPS
Rules policy to preserve the application hooking protection.
• Firewall Quarantine Options policies are not migrated (these policies were removed in version
8.0).
• Firewall Quarantine Rules policies are not migrated (these policies were removed in version
8.0).
• IPS Client Rules and Firewall Client Rules are not migrated.
NOTE: Policy assignments are carried over automatically in the migration unless inheritance
has been broken. Always review policy assignment after migrating policies.
Migration scenarios
Migrating policies to version 8.0 is similar from both 6.1 and 7.0 policies. This is true for all
platforms.
To version 8.0, do this...To migrate this version of Host Intrusion
Prevention...
6.1 • Install the Host IPS 8.0 extensions in ePolicy
Orchestrator.
McAfee Host Intrusion Prevention 8.0 Installation Guide30
Komentáře k této Příručce