These topics describe how to disable blocking action or force blocking action for all IPS rules:
About IPS blocking mode
Forcing all matched IPS rules to block traffic (CLI)
Forcing all matched IPS rules to block traffic (CLI)
Re‑enabling the blocking actions of all IPS rules (CLI)
About IPS blocking mode
IPS blocking mode is a platform-wide policy to allow, deny, or force blocking of traffic matched by IPS rules. IPS blocking mode is enabled by default. Only IPS rules with the blocking action block can drop matched traffic. The other states for IPS blocking mode (disabled and all) enable you to override the blocking actions of all IPS rules.
The following list describes the IPS blocking modes:
Enabled
When an IPS rule matches a traffic flow, the platform blocks or allows the traffic as specified by the block action of the rule.
Note
If the matched IPS rule specifies the block action value blockable, the system handles the matched traffic as if the block action value were noblock, except that you can override the blockable action on a per-rule basis only.
Disabled
All matched IPS rules act as detection-only rules, even rules that specify blocking. Disabling of IPS blocking mode is useful when you first enable IPS features on an existing deployment of a Network Security appliance.
Note
When IPS blocking is disabled, IPS rules cannot block malicious activity.
All
All matched IPS rules act as blocking rules, even rules that do not specify blocking.
Forced blocking is useful if you are testing the accuracy of every rule in an IPS policy by running the policy against known test traffic.
When an IPS rule matches a traffic flow, the system generates an IPS event and sends IPS event notifications (if notifications are configured). The action taken on the traffic flow is determined by two factors:
The IPS blocking mode on the appliance.
The blocking action specified by the matched IPS rule.
IPS Blocking Mode | Action Specified by the Matched IPS Rule | ||
|---|---|---|---|
block | noblock | blockable | |
|
|
|
|
|
|
|
|
|
|
|
|
The following caveats apply to IPS blocking mode:
The CLI configuration ips blockmode disabled, which disables blocking for all IPS rules, takes precedence over rule overrides specified for a vulnerability or IPS rule.
The CLI configuration ips blockmode all, which forces blocking for all IPS rules, takes precedence over rule overrides specified for a vulnerability or IPS rule. On such a system, traffic that matches an IPS rule that is suppressed (or suppressed and disabled) is not suppressed and is blocked.
Forcing all matched IPS rules to allow traffic (CLI)
On an IPS platform, IPS blocking mode is enabled by default.
If you want all IPS rules to pass matched traffic, disable IPS blocking mode. The appliance operates with standard malware rules in blocking mode (as specified in the malware rule definitions) but with IPS rules in detection-only mode, even for IPS rules that specify blocking. This configuration option is relevant only when the platform is deployed inline and the monitoring interface is configured for inline blocking.
Important
When IPS blocking mode is disabled, IPS rules with blocking action set to block are not allowed to block malicious activity detected in the matched traffic.
Prerequisites
Log in to the Web UI of the IPS platform as Admin.
Procedure
To disable the blocking actions specified by matched IPS rules:
Enable the CLI configuration mode.
hostname > enable hostname # configure terminalDisplay the status of IPS global settings.
In the following example, the platform blocks or allows matched traffic as specified by the block action of the rule (for interfaces configured for inline blocking). This is the default state.
hostname (config) # show ips status IPS enabled : yes IPS feature active : yes IPS feature licensed : yes Auto-update rules for an active policy : disabled IPS blockmode : enabled IPS blockmode last modified: 2019/02/07 05:00:22 IPS configuration status : Fully applied to system : yesConfigure the platform to pass all matched packets, even if the matched IPS rule specifies blocking.
hostname (config) # ips blockmode disabledVerify that you have disabled the blocking actions specified by matched IPS rules.
hostname (config) # show ips status IPS enabled : yes IPS feature active : yes IPS feature licensed : yes Auto-update rules for an active policy : disabled IPS blockmode : disabled IPS blockmode last modified: 2019/02/07 05:11:07 IPS configuration status : Fully applied to system : yesSave your changes.
hostname (config) # write memory
Forcing all matched IPS rules to block traffic (CLI)
On an IPS platform, IPS blocking mode is enabled by default.
You can force all matched IPS rules to block traffic. In this mode, all matched IPS rules act as blocking rules, regardless of the block action specified by the rule. This configuration option is relevant only when the platform is deployed inline and the monitoring interface is configured for inline blocking.
Prerequisites
Log in to the CLI of the IPS appliance as Admin.
Procedure
To force all matched IPS rules to block traffic:
Enable the CLI configuration mode.
hostname > enable hostname # configure terminalDisplay the status of IPS global settings.
In the following example, the platform has previously been configured to force all IPS rules to pass matched traffic.
hostname (config)) # show ips status IPS enabled : yes IPS feature active : yes IPS feature licensed : yes Auto-update rules for an active policy : disabled IPS blockmode : disabled IPS blockmode last modified: 2014/10/27 08:22:54 IPS configuration status : Fully applied to system : yesConfigure the platform to force all IPS rules to block matched traffic.
hostname (config) # ips blockmode allVerify that you have forced all IPS rules to block matched traffic.
hostname (config) # show ips status IPS enabled : yes IPS feature active : yes IPS feature licensed : yes Auto-update rules for an active policy : disabled IPS blockmode : all IPS blockmode last modified: 2018/10/27 08:39:17 IPS configuration status : Fully applied to system : yesSave your changes.
hostname (config) # write memory
Re‑enabling the blocking actions of all IPS rules (CLI)
This configuration option is relevant only when the platform is deployed inline and the monitoring interface is configured for inline blocking.
On an IPS platform, IPS blocking mode is enabled by default. The system blocks or allows monitored traffic as specified by the matched IPS rule. For testing purposes, you can change IPS blocking mode to disabled (monitoring-only mode) or to all (forced blocking). When testing is completed, restore IPS blocking mode so that the system resumes blocking malicious activity as specified by IPS rules.
Prerequisites
Log in to the CLI of the IPS appliance as Admin.
Procedure
To re-enable the blocking actions specified by matched IPS rules:
Enable the CLI configuration mode.
hostname > enable hostname # configure terminalDisplay the status of IPS global settings.
In the following example, the platform has previously been configured to disable blocking actions specified by matched IPS rules.
hostname (config) # show ips status IPS enabled : yes IPS feature active : yes IPS feature licensed : yes Auto-update rules for an active policy : disabled IPS blockmode : disabled IPS blockmode last modified: 2018/10/27 08:22:54 IPS configuration status : Fully applied to system : yesConfigure the platform to block or allow matched traffic as specified by the block action of the rule. Only traffic matched by IPS rules that specify the blocking action block will be blocked.
hostname (config) # no ips blockmodeVerify that you have forced all IPS rules to block matched traffic.
hostname (config) # show ips status IPS enabled : yes IPS feature active : yes IPS feature licensed : yes Auto-update rules for an active policy : disabled IPS blockmode : enabled IPS blockmode last modified: 2018/10/27 08:39:17 IPS configuration status : Fully applied to system : yesSave your changes.
hostname (config) # write memory