The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Beyond the basics: fine-tuning the IPS configuration

Prev Next

Based on the results of IPS detection and blocking activities performed by your IPS platform, you can customize the IPS detection and blocking features on your platform.

Configuring and applying custom IPS policies

You can apply custom IPS policies that you configure with specific rule-matching criteria or with specific rule-inclusion and rule-exclusion lists. For more information, see IPS policy configuration.

You also override traffic-blocking actions specified by IPS rules, globally across the appliance or for a specific vulnerability or IPS rules. For more information, see IPS rule action overrides.

Disabling auto add rules for standard IPS rules

When the Auto Add Rules option is enabled, the platform re-evaluates active IPS policies whenever standard (Trellix-provided) IPS rules are added, changed, or removed. For details, see Managing auto-addition of new IPS rules to active interfaces.

Updates to the standard IPS rules are distributed by Trellix through security content updates. Security content updates can be obtained through scheduled or explicit downloads from the Trellix Dynamic Threat Intelligence (DTI) cloud.

Overriding rules selected by active IPS policies

You can configure the IPS-enabled rules engine to override the blocking actions specified by IPS rules or signatures. The section IPS rule action overrides describes the following configuration options:

  • Disable or Force Blocking for All IPS Rules

  • Disable or Force Blocking for a Vulnerability or an IPS Rule from an IP Address

  • Suppress a Vulnerability or an IPS Rule from an IP Address

Creating and uploading custom IPS rules based on custom signatures

You can create and upload your own IPS content rules so that the IPS-enabled rules engine can detect specific intruder signatures present in the data packets in your network traffic. For more information, see IPS rules based on custom signatures.

Managing the volume of IPS event notifications

When you first activate IPS features, we recommend that you use the dual delivery mode for IPS event notification. If you need to reduce the volume of IPS event notifications that you analyze, you can change to confirmation delivery mode. For more information, see IPS event notifications.

Enabling IPS detection of reconnaissance activity

You can enable the platform to detect reconnaissance activity and trigger IPS reconnaissance events when attack patterns are detected. For more information, see IPS detection of reconnaissance activity.