Place systems in Adaptive mode so that Host Intrusion Prevention can create client rules automatically without user interaction.
Tip
Best practice:Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.Defining a network as trusted causes Firewall to create an internal bi-directional Allow rule with remote network criteria set to the trusted network. Any traffic to and from the trusted networks is allowed.
Adaptive mode analyzes events first for the most malicious attacks. If the activity is considered regular and needed for business, Host Intrusion Prevention creates client rules. By enabling Adaptive mode on representative clients, you can create a tuning configuration. You can then convert client rules to server-mandated policies. When tuning is complete, turn off Adaptive mode to tighten the system’s protection.
Run client systems in Adaptive mode for at least a week. In this time, client systems encounter all normal activity, including scheduled activity, such as backups or script processing. As activity occurs, Host Intrusion Prevention generates events and creates rules.