To add the condition to the example signature:
Steps:
Click Condition 1 so that it is highlighted.
Click AND in the Comparisons section.
The Add AND Comparison dialog opens.
Single Fixed Field Match.png)
For this example, select Single Fixed Field Match in the Comparison Type drop-down menu.
Select ipv4 from the Protocol list.
Because you selected IPv4, the Custom Attack Editor displays the IPv4-specific protocol fields on the following screen.
Configure the fields for the comparison you have chosen.
For this example, specify ipv4-destination-ip for the Protocol Field.
From the Operator drop-down list, select the matching criteria as Equals which means that the comparison criteria must be equal to the IP address entered.
Type the IP address in the Integer or IP to Match.
For this example, the value to match is "192.168.1.1".
(Optional) Uncheck Ignore Bitmask if you want to process the bitmask of the IP address.
Click Save.
Your comparison appears under Condition 1.
Click Add in the New Custom Attack window.
Verify that the attack definition is listed on the Native Trellix IPS Format tab.
.png)
Click Save to save the Trellix IPS Custom Attack in the Manager server database.
Make sure the Trellix IPS Custom Attack is saved in the database and also published in the policies.