New counters for dropped packets
Starting with this release, the Devices → <Admin Domain Name> → Devices → <Device Name> → Troubleshooting → Traffic Statistics → Dropped Packets tab displays the following new counters:
- Backend - Total number of miscellaneous packets dropped at back-end.
- Backplane - Total number of miscellaneous packets dropped at BMC switch.
- Frontend - Total number of miscellaneous packets dropped at front-end.
- Layer 2 Non-Errors - Total number of layer 2 packets dropped due to other reasons.
- NIC - Total number of miscellaneous packets dropped at NIC.
Additionally, the following counters are renamed:
| Prior 10.1.7.35 | 10.1.7.35 and above |
|---|---|
| Other Layer 2 Errors | Layer 2 Errors |
| Policy Response Actions - Firewall | Policy Response - Stateful Firewall |
| Policy Response Actions - IPS | Policy Response - IPS Attack |
| Policy Response Actions - IPv4 Quarantine | Policy Response - IPv4 Quarantine |
| Policy Response Actions - IPv6 Quarantine | Policy Response - IPv6 Quarantine |
Callback detector enhancements
With this release of 10.1, the callback detector files are available in the McAfee Update Server. Going forward, you must download the latest callback detectors from the McAfee Network Security Update Server to the Manager. The Download Callback Detectors page displays the latest 10 versions of the callback detectors.
To view the Download Callback Detectors page, go to Manager → <Admin Domain Name> → Updating → Download Callback Detectors.
Expiry restrictions for capacity license
Previously, the expiration date was displayed for production level capacity licenses in the Licenses page. Starting from this release of 10.1, the expiration date is no longer displayed for production level capacity licenses as they are perpetual.
To view the capacity license, go to System tab under Manager → <Admin Domain Name> → Setup → Licenses.
Terminology update in UI
This release contains the following terminology update in the UI to keep up with the global standard:
| Navigation Path | Prior 10.1.7.35 | 10.1.7.35 and later |
|---|---|---|
| Analysis → Threat Explorer | Blacklisted/Whitelisted under the Executable Classification column in the Top Executables table | Blocked/Allowed under the Executable Classification column in the Top Executables table |
| Analysis → Malware Files | Blacklist column under Individual Engine Confidence column | Block column under Individual Engine Confidence column |
| Manage Whitelist and Blacklist | Manage allow and block lists | |
| Analysis → Network Forensics | Under Suspicious Flows Panel → Suspicious activity indicators → Blacklisted executable | Under Suspicious Flows Panel → Suspicious activity indicators → Blocked executable |
| Analysis → Endpoint Executables | Manage Whitelist and Blacklist | Manage allow and block lists |
| Blacklisted/Whitelisted under the Classification column | Blocked/Allowed under the Classification column | |
| Double-click on an alert and go to EIA Details tab. Local Classification: Blacklisted/Whitelisted. | Double-click on an alert and go to EIA Details tab. Local Classification: Blocked/Allowed. | |
Analysis → Attack Log
|
Click Other Actions → Create Exception → Blacklist File Hash: < hash file> or double-click on an alert and go to Details tab. Select Blacklist. | Click Other Actions → Create Exception → Block File Hash: < hash file> or double-click on an alert and go to Details tab. Select Block. |
| Click Other Actions → Create Exception → Whitelist File Hash: <hash file> or double-click on an alert and go to Details tab. Select Whitelist. | Click Other Actions → Create Exception → Allow File Hash: < hash file> or double-click on an alert and go to Details tab. Select Allow. | |
| Policy → Intrusion Prevention → Exceptions → File Hashes | Whitelisted Hashes | Allowed Hashes |
Take Action -
|
Take Action -
|
|
| Import - On selecting, Import Whitelisted Hashes dialog is displayed. | Import - On selecting, Import Allowed Hashes dialog is displayed. | |
| Export Whitelist | Export Allowed | |
| Blacklisted Hashes | Blocked Hashes | |
Take Action -
|
Take Action -
|
|
| Import- On selecting, Import Blacklisted Hashes is displayed. | Import- On selecting, Import Blocked Hashes is displayed. | |
| Export Blacklist | Export Block List | |
| Policy → Intrusion Prevention → Exceptions → Domain Names | Callback Detection Whitelist | Callback Detection Exclusions |
| Import - On selecting, Import Whitelisted Domains dialog is displayed. | Import - On selecting, Import Allowed Domains dialog is displayed. | |
| IPS Inspection Whitelist | IPS Inspection Exclusions | |
| Policy → Intrusion Prevention → Exceptions | SSL Decryption Exceptions | SSL Decryption Exclusions |
| Policy → Intrusion Prevention → Policy Types → Advanced Malware Policies | New or an existing policy - Blacklist and Whitelist column under the Scanning Options section. | New or an existing policy - Allow and Block Lists column under the Scanning Options section. |
| Policy → Intrusion Prevention → Policy Types → Inspection Option Policies | Domain Name Whitelist Processing under tab Inspection Options → Advanced Callback Detection | Domain Name Exclusion List Processing under tab Inspection Options → Advanced Callback Detection |
| Blacklisted Text under tab Inspection Options → Web Server - Heuristic Analysis | Blocked Text under tab Inspection Options → Web Server - Heuristic Analysis |