The procedure to create an admin domain is the same for a domain created under the root or a domain created under a child of the root, and so on. You can create up to four levels of child domains under an admin domain. During child domain creation, you have the option of delegating Sensor interfaces from the parent for management by the child.
If you do not want at this time to allocate interfaces or allow Sensor addition, you may enable these options later.
To create an admin domain:Task
- Click Manager → <Admin Domain Name> → Setup → Admin Domains. The Admin Domains page is displayed.
-
Select the domain to which you want to add a child domain and then click
.
-
Type the required information. The red asterisks (*) denote required fields.
The tables below describe the fields.
Field Description Domain Name Enter a unique name for identifying the domain. For an enterprise, naming your domain after the specific network segment, department, or building is suggested: HR, Finance, Bldg1, Bldg1-Floor2. Contact Person Enter the name of the person responsible for the domain. This person should be someone who can be reached in case of emergency or other domain questions. E-mail Address Email address of the Contact Person. Title Title of the Contact Person. Contact Phone Number Phone number of the Contact Person. Company Phone Number Phone number of the Company where the Contact Person works. Organization Name of the Contact Person's employer company. Address Address of the Organization. City Name of the City where the Organization is located. State Name of the State where the Organization is located. Country Name of the Country where the Organization is located. You can choose to enter additional details like phone number and address while creating the domain.The fields mentioned below set restrictions on the child admin domain being created:Field Description Allow Child Admin Domains? If you select this check box, the administrator of the domain you are currently creating can create child admin domains for the domain. If you create a child admin domain and disallow the creation of further child admin domains, the new child domain cannot have its own children due to rule inheritance.
Allow Devices? If you select this check box, the administrator of the domain you are currently creating can add, edit, or delete physical Sensors. Otherwise, the domain is only permitted interface or sub-interface resources as allocated in Step5. If you create a child admin domain and disallow the adding of physical Sensors, any children of the new child domain are also disallowed from adding physical Sensors due to rule inheritance.
You can provide the following permissions to an admin domain:
- Create a child admin domain from the existing admin domain by selecting Allow Child Admin Domains?
- Add devices in the admin domain by selecting Allow Devices?
-
For IPS devices, select the IPS policy from
Default IPS Policy drop-down list. For the NTBA Policy and Worm Policy, the fields mentioned below are displayed:
Field Description Default NTBA Policy Sets the default NTBA Policy to be inherited by child admin domain resources. Several pre-configured policies are provided that encompass different network environments. Default Worm Policy Sets the default Worm policy to be inherited by child admin domains. -
Click
Save.
The Allocated Interfaces page appears.
- Click Allocate.
- Select a Sensor from Select an IPS sensor drop-down list to allocate interfaces/sub-interfaces to the child domain. You can allocate interfaces/sub-interfaces from one or more Sensors.
- Click Allocate. You may only select one interface from one Sensor at a time.
- Repeat until you have allocated all the interfaces you require.
-
Click
Finish.
The child admin domain you created appears at the bottom of the resource list of the domain in which it was created.