To select the IPS rules that your platform uses to analyze traffic at an interface, you apply an IPS policy to the interface. The rules engine detects IPS events by evaluating the selected rules against the monitored traffic. To select the IPS rules that your platform uses to analyze traffic at an interface, you apply an IPS policy to the interface. The rules engine detects IPS events by evaluating the selected rules against the monitored traffic.
To use the CLI to apply an IPS policy to an interface, use the ips apply command.
Prerequisites
Log in to the CLI of the IPS platform as Operator or Admin.
(Optional) If you need more specific rule-selection criteria than is provided by the default IPS policies, configure custom IPS policies. For more information, see IPS policy configuration.
Procedure
To apply policy-selected IPS rules to the traffic at an interface:
Enable the CLI configuration mode.
hostname > enable hostname # configure terminalDisplay the appliance interfaces and the current application of IPS policies to appliance interfaces.
In the following example, the appliance has two interfaces. A default IPS policy is active on one interface, and no IPS policy is active on the other interface.
hostname (config) # show ips interfaces Interface : A Policy applied : empty Rule count : 0 Interface : B Policy applied : empty Rule count : 0Note
For IPS platforms deployed in environments with asymmetric routing, apply the same IPS policy to both interfaces. If request and response packets traverse separate links to the two interfaces, the platform applies the same IPS rules to the upstream and downstream traffic.
Apply an IPS policy to an interface.
The following example applies the custom IPS policy named
myCustom1to both interfaces, replacing theFireEye_Defaulton interface A.hostname (config) # ips apply myCustom1 interface A hostname (config) # ips apply myCustom1 interface BVerify your changes.
hostname (config) # show ips interfaces Interface : A Policy applied : myCustom1 Rule count : 1002 Interface : B Policy applied : myCustom1 Rule count : 1002Note
For IPS platforms deployed in environments with asymmetric routing, apply the same IPS policy to both interfaces. If request and response packets traverse separate links to the two interfaces, the platform applies the same IPS rules to the upstream and downstream traffic.
Save your changes.
hostname (config) # write memory