Based on the results of IPS detection and blocking activities performed by your IPS platform, you can customize the IPS detection and blocking features on your platform.
Configuring and applying custom IPS policies
You can apply custom IPS policies that you configure with specific rule-matching criteria or with specific rule-inclusion and rule-exclusion lists. For more information, see IPS policy configuration.
You also override traffic-blocking actions specified by IPS rules, globally across the appliance or for a specific vulnerability or IPS rules. For more information, see IPS rule action overrides.
Disabling auto add rules for standard IPS rules
When the Auto Add Rules option is enabled, the platform re-evaluates active IPS policies whenever standard (Trellix-provided) IPS rules are added, changed, or removed. For details, see Managing auto-addition of new IPS rules to active interfaces.
Updates to the standard IPS rules are distributed by Trellix through security content updates. Security content updates can be obtained through scheduled or explicit downloads from the Trellix Dynamic Threat Intelligence (DTI) cloud.
Overriding rules selected by active IPS policies
You can configure the IPS-enabled rules engine to override the blocking actions specified by IPS rules or signatures. The section IPS rule action overrides describes the following configuration options:
Disable or Force Blocking for All IPS Rules
Disable or Force Blocking for a Vulnerability or an IPS Rule from an IP Address
Suppress a Vulnerability or an IPS Rule from an IP Address
Creating and uploading custom IPS rules based on custom signatures
You can create and upload your own IPS content rules so that the IPS-enabled rules engine can detect specific intruder signatures present in the data packets in your network traffic. For more information, see IPS rules based on custom signatures.
Managing the volume of IPS event notifications
When you first activate IPS features, we recommend that you use the dual delivery mode for IPS event notification. If you need to reduce the volume of IPS event notifications that you analyze, you can change to confirmation delivery mode. For more information, see IPS event notifications.
Enabling IPS detection of reconnaissance activity
You can enable the platform to detect reconnaissance activity and trigger IPS reconnaissance events when attack patterns are detected. For more information, see IPS detection of reconnaissance activity.