The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Applying an IPS policy to monitoring and management interfaces (CLI)

Prev Next

To select the IPS rules that your platform uses to analyze traffic at an interface, you apply an IPS policy to the interface. The rules engine detects IPS events by evaluating the selected rules against the monitored traffic. To select the IPS rules that your platform uses to analyze traffic at an interface, you apply an IPS policy to the interface. The rules engine detects IPS events by evaluating the selected rules against the monitored traffic.

To use the CLI to apply an IPS policy to an interface, use the ips apply command.

Prerequisites
  • Log in to the CLI of the IPS platform as Operator or Admin.

  • (Optional) If you need more specific rule-selection criteria than is provided by the default IPS policies, configure custom IPS policies. For more information, see IPS policy configuration.

Procedure

To apply policy-selected IPS rules to the traffic at an interface:

  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Display the appliance interfaces and the current application of IPS policies to appliance interfaces.

    In the following example, the appliance has two interfaces. A default IPS policy is active on one interface, and no IPS policy is active on the other interface.

    hostname (config) # show ips interfaces
    Interface : A
    	Policy applied : empty
    	Rule count : 0
    Interface : B
    	Policy applied : empty
    	Rule count : 0

    Note

    For IPS platforms deployed in environments with asymmetric routing, apply the same IPS policy to both interfaces. If request and response packets traverse separate links to the two interfaces, the platform applies the same IPS rules to the upstream and downstream traffic.

  3. Apply an IPS policy to an interface.

    The following example applies the custom IPS policy named myCustom1 to both interfaces, replacing the FireEye_Default on interface A.

    hostname (config) # ips apply myCustom1 interface A
    hostname (config) # ips apply myCustom1 interface B
  4. Verify your changes.

    hostname (config) # show ips interfaces
    Interface : A
    	Policy applied : myCustom1
    	Rule count : 1002
    Interface : B
    	Policy applied : myCustom1
    	Rule count : 1002

    Note

    For IPS platforms deployed in environments with asymmetric routing, apply the same IPS policy to both interfaces. If request and response packets traverse separate links to the two interfaces, the platform applies the same IPS rules to the upstream and downstream traffic.

  5. Save your changes.

    hostname (config) # write memory