The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Action overrides to all IPS rules

Prev Next

These topics describe how to disable blocking action or force blocking action for all IPS rules:

  • About IPS blocking mode

  • Forcing all matched IPS rules to block traffic (CLI)

  • Forcing all matched IPS rules to block traffic (CLI)

  • Re‑enabling the blocking actions of all IPS rules (CLI)

About IPS blocking mode

IPS blocking mode is a platform-wide policy to allow, deny, or force blocking of traffic matched by IPS rules. IPS blocking mode is enabled by default. Only IPS rules with the blocking action block can drop matched traffic. The other states for IPS blocking mode (disabled and all) enable you to override the blocking actions of all IPS rules.

The following list describes the IPS blocking modes:

Enabled

When an IPS rule matches a traffic flow, the platform blocks or allows the traffic as specified by the block action of the rule.

Note

If the matched IPS rule specifies the block action value blockable, the system handles the matched traffic as if the block action value were noblock, except that you can override the blockable action on a per-rule basis only.

Disabled

All matched IPS rules act as detection-only rules, even rules that specify blocking. Disabling of IPS blocking mode is useful when you first enable IPS features on an existing deployment of a Network Security appliance.

Note

When IPS blocking is disabled, IPS rules cannot block malicious activity.

All

All matched IPS rules act as blocking rules, even rules that do not specify blocking.

Forced blocking is useful if you are testing the accuracy of every rule in an IPS policy by running the policy against known test traffic.

When an IPS rule matches a traffic flow, the system generates an IPS event and sends IPS event notifications (if notifications are configured). The action taken on the traffic flow is determined by two factors:

  • The IPS blocking mode on the appliance.

  • The blocking action specified by the matched IPS rule.

IPS Blocking Mode

Action Specified by the Matched IPS Rule

block

noblock

blockable

Enabled

block

allow

allow

Disabled

allow

allow

allow

All

block

block

block

The following caveats apply to IPS blocking mode:

  • The CLI configuration ips blockmode disabled, which disables blocking for all IPS rules, takes precedence over rule overrides specified for a vulnerability or IPS rule.

  • The CLI configuration ips blockmode all, which forces blocking for all IPS rules, takes precedence over rule overrides specified for a vulnerability or IPS rule. On such a system, traffic that matches an IPS rule that is suppressed (or suppressed and disabled) is not suppressed and is blocked.

Forcing all matched IPS rules to allow traffic (CLI)

On an IPS platform, IPS blocking mode is enabled by default.

If you want all IPS rules to pass matched traffic, disable IPS blocking mode. The appliance operates with standard malware rules in blocking mode (as specified in the malware rule definitions) but with IPS rules in detection-only mode, even for IPS rules that specify blocking. This configuration option is relevant only when the platform is deployed inline and the monitoring interface is configured for inline blocking.

Important

When IPS blocking mode is disabled, IPS rules with blocking action set to block are not allowed to block malicious activity detected in the matched traffic.

Prerequisites
  • Log in to the Web UI of the IPS platform as Admin.

Procedure

To disable the blocking actions specified by matched IPS rules:

  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Display the status of IPS global settings.

    In the following example, the platform blocks or allows matched traffic as specified by the block action of the rule (for interfaces configured for inline blocking). This is the default state.

    hostname (config) # show ips status
    
    IPS enabled          : yes
    IPS feature active   : yes
    IPS feature licensed : yes
    Auto-update rules for an active policy : disabled
     
    IPS blockmode : enabled
    IPS blockmode last modified: 2019/02/07 05:00:22
     
    IPS configuration status : 
            Fully applied to system : yes
  3. Configure the platform to pass all matched packets, even if the matched IPS rule specifies blocking.

    hostname (config) # ips blockmode disabled
  4. Verify that you have disabled the blocking actions specified by matched IPS rules.

    hostname (config) # show ips status
     
    IPS enabled          : yes
    IPS feature active   : yes
    IPS feature licensed : yes
     
    Auto-update rules for an active policy : disabled
     
    IPS blockmode : disabled
    IPS blockmode last modified: 2019/02/07 05:11:07
     
     
    IPS configuration status : 
            Fully applied to system : yes
  5. Save your changes.

    hostname (config) # write memory
Forcing all matched IPS rules to block traffic (CLI)

On an IPS platform, IPS blocking mode is enabled by default.

You can force all matched IPS rules to block traffic. In this mode, all matched IPS rules act as blocking rules, regardless of the block action specified by the rule. This configuration option is relevant only when the platform is deployed inline and the monitoring interface is configured for inline blocking.

Prerequisites
  • Log in to the CLI of the IPS appliance as Admin.

Procedure

To force all matched IPS rules to block traffic:

  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Display the status of IPS global settings.

    In the following example, the platform has previously been configured to force all IPS rules to pass matched traffic.

    hostname (config)) # show ips status
     
    IPS enabled          : yes
    IPS feature active   : yes
    IPS feature licensed : yes
     
    Auto-update rules for an active policy : disabled
     
    IPS blockmode : disabled
    IPS blockmode last modified: 2014/10/27 08:22:54
     
     
    IPS configuration status : 
            Fully applied to system : yes
  3. Configure the platform to force all IPS rules to block matched traffic.

    hostname (config) # ips blockmode all
  4. Verify that you have forced all IPS rules to block matched traffic.

    hostname (config) # show ips status
     
    IPS enabled          : yes
    IPS feature active   : yes
    IPS feature licensed : yes
     
    Auto-update rules for an active policy : disabled
     
    IPS blockmode : all
    IPS blockmode last modified: 2018/10/27 08:39:17
     
     
    IPS configuration status : 
            Fully applied to system : yes
  5. Save your changes.

    hostname (config) # write memory
Re‑enabling the blocking actions of all IPS rules (CLI)

This configuration option is relevant only when the platform is deployed inline and the monitoring interface is configured for inline blocking.

On an IPS platform, IPS blocking mode is enabled by default. The system blocks or allows monitored traffic as specified by the matched IPS rule. For testing purposes, you can change IPS blocking mode to disabled (monitoring-only mode) or to all (forced blocking). When testing is completed, restore IPS blocking mode so that the system resumes blocking malicious activity as specified by IPS rules.

Prerequisites
  • Log in to the CLI of the IPS appliance as Admin.

Procedure

To re-enable the blocking actions specified by matched IPS rules:

  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Display the status of IPS global settings.

    In the following example, the platform has previously been configured to disable blocking actions specified by matched IPS rules.

    hostname (config) # show ips status
     
    IPS enabled          : yes
    IPS feature active   : yes
    IPS feature licensed : yes
     
    Auto-update rules for an active policy : disabled
     
    IPS blockmode : disabled
    IPS blockmode last modified: 2018/10/27 08:22:54
     
     
    IPS configuration status : 
            Fully applied to system : yes
  3. Configure the platform to block or allow matched traffic as specified by the block action of the rule. Only traffic matched by IPS rules that specify the blocking action block will be blocked.

    hostname (config) # no ips blockmode
  4. Verify that you have forced all IPS rules to block matched traffic.

    hostname (config) # show ips status
     
    IPS enabled          : yes
    IPS feature active   : yes
    IPS feature licensed : yes
     
    Auto-update rules for an active policy : disabled
     
    IPS blockmode : enabled
    IPS blockmode last modified: 2018/10/27 08:39:17
     
     
    IPS configuration status : 
            Fully applied to system : yes
  5. Save your changes.

    hostname (config) # write memory