This topic covers the following information:
Overview of IPS policies
Default IPS policies
Custom IPS policies
Overview of IPS policies
An IPS policy is a named set of criteria for selecting IPS rules from the database of an IPS platform. The platform includes a set of default IPS policies, and you can configure custom IPS policies.
You activate an IPS policy by applying it to monitoring interfaces on your appliance. If your appliance has more than one monitoring interface, you can apply an IPS policy to each interface separately.
While an IPS policy is active, the monitoring interface to which the policy is applied is also said to be active.
When you apply an IPS policy to a monitoring interface, the IPS-enabled rules engine uses the policy-selected IPS rules to analyze the network traffic traversing the interface. When the rules engine matches a traffic flow to an active IPS rule, the platform generates an IPS event. If a client-targeted IPS event is found to correlate with MVX-verified malware attacks detected by standard Network Security features, the platform generates an IPS alert for the IPS event.
If no IPS policies are active on an IPS platform, the appliance uses only standard Network Security content rules to analyze traffic passing through the monitoring interfaces. Threat protection for that traffic is limited to detection of HTTP-based malware attacks directed at client machines.
Default IPS policies
An IPS system provides default policies that cover all basic use cases. You cannot modify or delete these policies. Default IPS policies specify criteria for selecting IPS rules that detect threats that target a specific type of host (client machine, host machine, or both) and that fall within a specific range of attack severity levels (on a scale from 1 through 10).
The following table lists the default IPS policies and each policy's the rule-selection attributes.
Default IPS policy | Values of rule-matching attributes | ||
|---|---|---|---|
attack-target | min-severity | max-severity | |
Comprehensive Selects both client-centric and server-centric rules, regardless of the attack severity level. | client, server | 1 | 10 |
Default_client_protection Selects server-centric rules with an attack severity level of 7 or higher. | client | 7 | 10 |
Default_server_protection Selects server-centric rules with an attack severity level of 7 or higher. | server | 7 | 10 |
FireEye_default Selects both client-centric and server-centric rules with an attack severity of 7 or higher. | client, server | 7 | 10 |
The default IPS policies are typically sufficient for your initial baselining. If you want to refine the IPS rule-selection criteria, you can use custom IPS policies.
Custom IPS policies
Depending on the vulnerabilities of your network and the types of network threats received, certain IPS rules or types of rules might not be critical to the security of your environment. To reduce the incidence of events generated by noisy IPS rules, you can configure custom policies that fine‑tune the rule selection criteria.
You must specify values for the attack target type and range of attack severity level. You can configure optional criteria based on attack category, attack subcategory, and protocol used as the attack vector. You can configure optional rule exclusion and rule inclusions based on signature ID.