The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Activating IPS processing

Prev Next

You can enable IPS capabilities by using either the Web UI or the CLI to apply IPS policies to monitoring interfaces:

  • About activating IPS processing

  • Activating IPS processing (Web UI)

  • Activating IPS processing (CLI)

About activating IPS processing

IPS features are not activated until you apply IPS policies to monitoring interfaces. Without IPS policies applied to monitoring interfaces, the appliance functions as a standard Network Security appliance that detects and, if deployed and configured inline, can block client-centric HTTP-based malware.

The following IPS policies are provided by default:

  • FireEye_Default—Detects client-directed and server-directed threats of critical severity (levels 7 through 10).

  • Comprehensive—Detects client-directed and server-directed threats of all severity (levels 1 through 10).

  • Default_Server_Protection—Detects server-directed threats of critical severity.

  • Default_Client_Protection—Detects client-directed threats of critical severity.

For detailed information about default IPS policies, see IPS policies. For detailed information about selecting the IPS rules that analyze your network traffic, see Applying an IPS policy to monitoring interfaces (web UI) or Applying an IPS policy to monitoring interfaces (CLI).

You can activate IPS processing by using either the Web UI or the CLI.

Activating IPS processing (Web UI)

To use the Web UI to activate IPS processing on an IPS appliance, use the IPS Configuration page.

Prerequisites
  • Log In to the appliance Web UI as Operator or Admin.

Procedure

To apply a default IPS policy to a monitoring interface:

  1. Choose IPS > Configure to display the association of monitoring interfaces to IPS policies.

  2. In the row for the IPS policy you want to apply, click Apply in the Actions column.

    Note

    When you first activate IPS features, we recommend that you use the FireEye_Default IPS policy.

  3. Select the monitoring interfaces you want to associate with the policy.

  4. Click Apply, and then click OK.

    The table row for the IPS policy reflects your configuration changes:

    • The Active on Interfaces column displays the letter designator for the interface associated with the policy.

    • The Rules Enabled column displays the number of IPS rules in the appliance database that match the selection criteria specified by the policy. To see a list of the active rules, you can generate the IPS policy configuration summary report or the IPS policy configuration details report.

    • The Actions column displays the actions available for the policy.

    After a few minutes, IPS event detection results are displayed in the Web UI and are available in reports.

Activating IPS processing (CLI)

This topic describes how to use the CLI to activate IPS processing on an IPS appliance.

Prerequisites

Before you begin activating IPS features with default IPS policies, perform the following prerequisite tasks:

  • Log in to the appliance CLI as Operator or Admin.

Procedure

To apply a default IPS policy to a monitoring interface:

  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Display the appliance interfaces and the current application of IPS policies to appliance interfaces.

    In the following example, the appliance has two monitoring interfaces and no IPS policies are active on the interfaces.

    hostname # show ips interfaces
    Interface : A
            Policy applied : empty
            Rule count : 0
    Interface : B
            Policy applied : empty
            Rule count : 0
  3. Apply an IPS policy to each monitoring interface.

    Note

    For IPS platforms deployed in environments with asymmetric routing, apply the same IPS policy to both monitoring interfaces. If request and response packets traverse separate links to the two monitoring interfaces, the platform applies the same IPS rules to the upstream and downstream traffic.

    In the following example, the IPS policy named FireEye_Default is applied to interface A, and the IPS policy named Comprehensive is applied to interface B.

    hostname (config) # ips apply FireEye_Default interface A
    hostname (config) # ips apply Comprehensive interface B
    hostname (config) # show ips interfaces
    Interface : A
            Policy applied : FireEye_Default
            Rule count : 2640
    Interface : B
            Policy applied : Comprehensive
            Rule count : 6882
  4. Save your changes.

    hostname (config) # write memory
  5. After a few minutes, IPS event detection results are displayed in the Web UI and are available in reports.