Trend Micro™ Network VirusWall™ Enforcer 2500 Administrator’s Guide
1
-
58
Distribution Switch and Access Switch Policies
This section includes a few sample policies that apply to the distribution switch and
access switch. Policies on this device should address endpoint hosts and scan for
network viruses. You can configure these policies with the assumption that another
Network VirusWall Enforcer 2500 device is between the core switch and WAN
module.
The first policy,
, specifically handles all traffic from Guest hosts. Deploy
Real-time Scan as a remedy to ensure that their computers do not introduce security
threats into the network.
Settings
Details
Endpoint
Settings
•
Policy name
: Guest
•
Policy comment
: This policy should be above authenticated
users if using agentless detection.
•
Agent type
:
Agentless
•
Agent deployment method
: ActiveX
•
Endpoint operating system
: Disable endpoint detection for
non-Windows operating systems
•
Compliant endpoint reassessment
: 1 day
•
Non-compliant endpoint reassessment
: 15 minutes
Authenticati
on and
Network
Zones
Settings
•
Authentication
: Apply policy to authenticated users
•
Endpoint Network Zones
: Any Network Zone
•
Packet Destination Network Zones
: Any Network Zone
•
TCP Protocol Ports
All ports
•
UDP Protocol Ports
All ports
•
Daily Schedule
: Everyday
•
Hourly Schedule
: All Day
T
ABLE
1-11.
Priority 1: Sample Distribution Switch and Access Switch Policy
Scenario