All Central Manager policies (Trellix IPS-defined and user-defined) are synchronized with the Managers. While viewing the policies from the added Managers, the Central Manager policy names have NSCM prefixed to differentiate them from the Manager policies. For example, a Default Prevention policy defined in the Central Manager will be seen as NSCM Default Prevention in the Manager IPS Policy Editor. The same applies to user-defined Central Manager policies also.
The Central Manager policies are non-editable in the Managers. The Central Manager Attack Defaults settings are merged with the Central Manager policy. The Managers Attack Defaults settings do not affect any Central Manager policy and vice versa.
Each Manager must import signature sets independently. The policies and attack set profiles are evaluated based on the Manager signature set.
If the Central Manager removes a policy and the policy is being used in a Manager, then, during synchronization, the Central Manager policy in the Manager is renamed and the ownership changed to that of the Manager. A fault is raised in the Manager indicating that the policy has not been removed in that Manager.
For more information on configuring policies, refer to the chapter Working with IPS policies.
Configuring policy synchronization
The Policy tab in Devices → <Admin Domain Name> → Manager Management → Synchronization page allows you to view and synchronize configurations between the Central Manager and all the Managers.
Field | Description |
|---|---|
Synchronization Type |
|
Manager Name | Name of the Manager added |
Synchronization Required |
|
Synchronization Status |
|
To trigger manual synchronization with the Manager, click Synchronize. | |
To individually synchronize configurations between a Manager and the Central Manager, go to Devices → <Admin Domain Name> → <Manager Name> → Synchronization and click on Policy tab.
Field | Description |
|---|---|
Synchronization Type |
|
Manager Name | Name of the Manager added |
Last Synchronized | Time when last synchronization took place. Time is displayed as per the client time zone. For more information, see Viewing the server/client date and time. |
Synchronization Required | If synchronization is required or not
|
Reason | Reason for synchronization |
Synchronization Status |
|
To trigger synchronization with the Manager, click Synchronize. | |
Note
You can also access Synchronize Policies menu from Policy → Intrusion Prevention.
Note
If the Central Manager contains a rule object with more than 10 entries, the Central Manager synchronizes only those rule objects containing 10 entries or lesser with a Manager running on or before 10.1.7.55.
Scheduling policy synchronization
You can configure the polices to be synchronized at regular time intervals. To set the policy scheduler in Central Manager, do the following:
Select Manager → Setup → Synchronization → Policy Scheduler
Note
Yes is selected by default in the Automate Synchronization field of the Policy Scheduler section. Select No to turn off the scheduled synchronization.
Select time from the drop-down list of the Recur every field.
Click Save.