You can create a custom IPS policy by cloning an existing IPS policy. The new policy inherits the match attributes and (if the original policy is a custom policy) any rule-exclusion and rule-inclusion attributes. You can clone an IPS policy that is active or inactive, but the new policy is inactive until you apply it to a monitoring interface.
This topic describes how to clone a default or custom IPS policy using the CLI.
Prerequisites
Log in to the CLI of the IPS appliance CLI as Operator or Admin.
To create a clone of an IPS policy:
Enable the CLI configuration mode.
hostname > enable hostname # configure terminalCreate a clone of an IPS policy.
The following example creates a clone of the FireEye_Default default policy and names the clone myCustom1.
hostname (config) # ips policy FireEye_Default clone myCustom1Display the attributes of the new IPS policy.
The following example shows that the newly created custom policy has the same match attributes as the Comprehensive default IPS policy.
hostname (config) # show ips policies myCustom1 Policy attributes active : no writable : yes modified_date : 2014/09/26 08:55:55 version : 1 Match attributes of policy : attack-target : client attack-target : server min-severity: 0 max-severity : 10 Fingerprint of policy : 2014/09/26 08:55:55 | 791c1c0bcd3b604630616acac14a96b1(Optional) If you want to modify the rule-matching attributes of the new policy, see Editing the rule match attributes of an IPS policy (CLI).
(Optional) If you want to modify the rule exclusion or inclusion attributes of the new policy, see Editing the rule inclusion and exclusion attributes of an IPS policy (CLI).
Save your changes.
hostname (config) # write memory