4-13
Installing Management Center for Cisco Security Agents 5.2
78-17916-01
Chapter 4 Quick Start Configuration
Configure a Rule Module
This quarantine list updates automatically (dynamically) as logged quarantined
files are received. You can use a file access control rule to permanently quarantine
a known virus as shown in this example.
Note Cisco recommends that you do not edit the preconfigured policies shipped with
the Management Center for Cisco Security Agents, but instead add new policies
to groups for any changes you might want.
To configure this file quarantine rule module, do the following.
Step 1 Move the mouse over Configuration in the menu bar and select Rule Modules
[Windows] from the drop-down list that appears. The Windows Rule Module list
view appears.
Step 2 Click the New button to create a new module. This takes you to the Rule Module
configuration page. See
Figure 4-5.
Step 3 In the configuration view, enter the Name Quarantined Application Module. Note
that names are case insensitive, must start with an alphabetic character, can be up
to 64 characters long. Spaces are also allowed in names.
Step 4 Enter a Description of your module. We’ll enter Module to quarantine an
application.
Step 5 Click the Save button. (We will not use State Sets in this example.)
Now we add our file access rule to this module.