The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

About IPS policies

Prev Next

This topic covers the following information:

  • Overview of IPS policies

  • Default IPS policies

  • Custom IPS policies

Overview of IPS policies

An IPS policy is a named set of criteria for selecting IPS rules from the database of an IPS platform. The platform includes a set of default IPS policies, and you can configure custom IPS policies.

  • You activate an IPS policy by applying it to monitoring interfaces on your appliance. If your appliance has more than one monitoring interface, you can apply an IPS policy to each interface separately.

  • While an IPS policy is active, the monitoring interface to which the policy is applied is also said to be active.

When you apply an IPS policy to a monitoring interface, the IPS-enabled rules engine uses the policy-selected IPS rules to analyze the network traffic traversing the interface. When the rules engine matches a traffic flow to an active IPS rule, the platform generates an IPS event. If a client-targeted IPS event is found to correlate with MVX-verified malware attacks detected by standard Network Security features, the platform generates an IPS alert for the IPS event.

If no IPS policies are active on an IPS platform, the appliance uses only standard Network Security content rules to analyze traffic passing through the monitoring interfaces. Threat protection for that traffic is limited to detection of HTTP-based malware attacks directed at client machines.

Default IPS policies

An IPS system provides default policies that cover all basic use cases. You cannot modify or delete these policies. Default IPS policies specify criteria for selecting IPS rules that detect threats that target a specific type of host (client machine, host machine, or both) and that fall within a specific range of attack severity levels (on a scale from 1 through 10).

The following table lists the default IPS policies and each policy's the rule-selection attributes.

Default IPS policy

Values of rule-matching attributes

attack-target

min-severity

max-severity

Comprehensive

Selects both client-centric and server-centric

rules, regardless of the attack severity level.

client, server

1

10

Default_client_protection

Selects server-centric rules with an attack

severity level of 7 or higher.

client

7

10

Default_server_protection

Selects server-centric rules with an attack

severity level of 7 or higher.

server

7

10

FireEye_default

Selects both client-centric and server-centric

rules with an attack severity of 7 or higher.

client, server

7

10

The default IPS policies are typically sufficient for your initial baselining. If you want to refine the IPS rule-selection criteria, you can use custom IPS policies.

Custom IPS policies

Depending on the vulnerabilities of your network and the types of network threats received, certain IPS rules or types of rules might not be critical to the security of your environment. To reduce the incidence of events generated by noisy IPS rules, you can configure custom policies that fine‑tune the rule selection criteria.

You must specify values for the attack target type and range of attack severity level. You can configure optional criteria based on attack category, attack subcategory, and protocol used as the attack vector. You can configure optional rule exclusion and rule inclusions based on signature ID.