The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Cloning an IPS policy (CLI)

Prev Next

You can create a custom IPS policy by cloning an existing IPS policy. The new policy inherits the match attributes and (if the original policy is a custom policy) any rule-exclusion and rule-inclusion attributes. You can clone an IPS policy that is active or inactive, but the new policy is inactive until you apply it to a monitoring interface.

This topic describes how to clone a default or custom IPS policy using the CLI.

Prerequisites
  • Log in to the CLI of the IPS appliance CLI as Operator or Admin.

To create a clone of an IPS policy:

  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Create a clone of an IPS policy.

    The following example creates a clone of the FireEye_Default default policy and names the clone myCustom1.

    hostname (config) # ips policy FireEye_Default clone myCustom1
  3. Display the attributes of the new IPS policy.

    The following example shows that the newly created custom policy has the same match attributes as the Comprehensive default IPS policy.

    hostname (config) # show ips policies myCustom1
    Policy attributes
            active : no
            writable : yes
            modified_date : 2014/09/26 08:55:55
            version : 1
     
    Match attributes of policy : 
            attack-target : client
            attack-target : server
            min-severity: 0
            max-severity : 10
     
    Fingerprint of policy : 
    2014/09/26 08:55:55 | 791c1c0bcd3b604630616acac14a96b1
  4. (Optional) If you want to modify the rule-matching attributes of the new policy, see Editing the rule match attributes of an IPS policy (CLI).

  5. (Optional) If you want to modify the rule exclusion or inclusion attributes of the new policy, see Editing the rule inclusion and exclusion attributes of an IPS policy (CLI).

  6. Save your changes.

    hostname (config) # write memory