You can enable IPS capabilities by using either the Web UI or the CLI to apply IPS policies to monitoring interfaces:
About activating IPS processing
Activating IPS processing (Web UI)
Activating IPS processing (CLI)
About activating IPS processing
IPS features are not activated until you apply IPS policies to monitoring interfaces. Without IPS policies applied to monitoring interfaces, the appliance functions as a standard Network Security appliance that detects and, if deployed and configured inline, can block client-centric HTTP-based malware.
The following IPS policies are provided by default:
FireEye_Default—Detects client-directed and server-directed threats of critical severity (levels 7 through 10).
Comprehensive—Detects client-directed and server-directed threats of all severity (levels 1 through 10).
Default_Server_Protection—Detects server-directed threats of critical severity.
Default_Client_Protection—Detects client-directed threats of critical severity.
For detailed information about default IPS policies, see IPS policies. For detailed information about selecting the IPS rules that analyze your network traffic, see Applying an IPS policy to monitoring interfaces (web UI) or Applying an IPS policy to monitoring interfaces (CLI).
You can activate IPS processing by using either the Web UI or the CLI.
Activating IPS processing (Web UI)
To use the Web UI to activate IPS processing on an IPS appliance, use the IPS Configuration page.
Prerequisites
Log In to the appliance Web UI as Operator or Admin.
Procedure
To apply a default IPS policy to a monitoring interface:
Choose IPS > Configure to display the association of monitoring interfaces to IPS policies.
In the row for the IPS policy you want to apply, click Apply in the Actions column.
Note
When you first activate IPS features, we recommend that you use the FireEye_Default IPS policy.
Select the monitoring interfaces you want to associate with the policy.
Click Apply, and then click OK.
The table row for the IPS policy reflects your configuration changes:
The Active on Interfaces column displays the letter designator for the interface associated with the policy.
The Rules Enabled column displays the number of IPS rules in the appliance database that match the selection criteria specified by the policy. To see a list of the active rules, you can generate the IPS policy configuration summary report or the IPS policy configuration details report.
The Actions column displays the actions available for the policy.
After a few minutes, IPS event detection results are displayed in the Web UI and are available in reports.
Activating IPS processing (CLI)
This topic describes how to use the CLI to activate IPS processing on an IPS appliance.
Prerequisites
Before you begin activating IPS features with default IPS policies, perform the following prerequisite tasks:
Log in to the appliance CLI as Operator or Admin.
Procedure
To apply a default IPS policy to a monitoring interface:
Enable the CLI configuration mode.
hostname > enable hostname # configure terminalDisplay the appliance interfaces and the current application of IPS policies to appliance interfaces.
In the following example, the appliance has two monitoring interfaces and no IPS policies are active on the interfaces.
hostname # show ips interfaces Interface : A Policy applied : empty Rule count : 0 Interface : B Policy applied : empty Rule count : 0Apply an IPS policy to each monitoring interface.
Note
For IPS platforms deployed in environments with asymmetric routing, apply the same IPS policy to both monitoring interfaces. If request and response packets traverse separate links to the two monitoring interfaces, the platform applies the same IPS rules to the upstream and downstream traffic.
In the following example, the IPS policy named
FireEye_Defaultis applied to interface A, and the IPS policy namedComprehensiveis applied to interface B.hostname (config) # ips apply FireEye_Default interface A hostname (config) # ips apply Comprehensive interface B hostname (config) # show ips interfaces Interface : A Policy applied : FireEye_Default Rule count : 2640 Interface : B Policy applied : Comprehensive Rule count : 6882Save your changes.
hostname (config) # write memoryAfter a few minutes, IPS event detection results are displayed in the Web UI and are available in reports.