Manage IPS Rulesets
The 'IPS Rules' interface displays a list of currently loaded IPS rulesets. Each ruleset contains settings to allow or block specific data packets.
To open the IPS Rules interface
- Click 'Services' > 'Intrusion Prevention' in the left-hand menu
- Click the 'IPS Rules' tab
Rules Table - Column Descriptions |
|
---|---|
Column |
Description |
Rule filename |
The name of the .rules file that contains the constituent rules of the ruleset. |
Rules count |
Indicates the number of constituent rules in the rule set. |
Actions |
Displays control buttons for the ruleset. - The checkbox allows the administrator to switch the ruleset between enabled and disabled states. / - Indicates the application policy of the
ruleset and enables the administrator to toggle the policy. See
Changing
application policy of rulesets for more details. - Removes the ruleset. |
The interface allows the administrator to:
The rulesets can be enabled or disabled individually or collectively from the Rules interface.
- To enable or disable a single ruleset, select or unselect the checkbox beside the ruleset in the 'Actions' column
- To enable inactive rulesets collectively, select the rules by marking the checkboxes at the left of the rulesets to be enabled and click the 'Enable' button from the bottom of the right pane.
- To disable active rulesets collectively, select the rules by marking the checkboxes at the left of the rulesets to be disabled and click the 'Disable' button from the bottom of the right pane.
- After making the changes, click the Apply button in the confirmation pane that appears at the top to apply the changes.
Changing
application policy of rulesets
A ruleset can be applied in two ways:
- Alert Policy - The IPS generates an alert when a data packet matching a rule in the ruleset is encountered and passes the packet. The policy is indicated by alert icon
- Drop Policy - The IPS blocks the data packet matching a rule in the ruleset without generating an alert. The policy is indicated by shield icon
The administrator can toggle the application policy for individual rulesets or for group of rulesets.
- To toggle the policy of a ruleset from 'Alert' policy to 'Drop' policy, click the 'Alert' icon in the row of the ruleset under the 'Actions' column
- To toggle the policy of a ruleset from 'Drop' policy to 'Alert' policy, click the 'Shield' icon in the row of the ruleset under the 'Actions' column
- To toggle the policy of a group of rulesets with 'Alert' policy to 'Drop' policy, select the rulesets by marking the checkboxes at the left of the ruleset file names and click the 'Drop' button at the bottom of the interface
- To toggle the policy of a group of rulesets with 'Drop' policy to 'Alert' policy, select the rulesets by marking the checkboxes at the left of the ruleset file names and click the 'Alert' button at the bottom of the interface
- After making the changes, click the Apply button in the confirmation pane that appears at the top to apply the changes.
Unwanted rulesets can be removed from Comodo Dome Firewall from the Rules interface.
- To remove a single ruleset click the delete icon in the row of the ruleset filename, under 'Actions' column and click 'OK' in the confirmation dialog.
- To remove a group of rulesets collectively, select the them by marking the checkboxes at the left of the ruleset file names and click the 'Delete' button at the bottom of the interface. Click 'OK' in the confirmation dialog.