The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring an alert policy exception using the CLI

Prev Next

Follow these steps to configure an alert policy exception using the CLI.

The syntax of the configuration command is as follows:

policymgr signature {id <sigID> | name <sigName> | category <attackCategory> | name all}
interface {<portPair> | ALL | MGMT} 
src {<srcIP>/<prefix> | any | any-v6} 
dst {<dstIP>/<prefix> | any | any-v6}
action <actionType>

The command variables are defined as follows:

<sigID>

The eight-digit signature ID for a single alert rule.

<sigName>

The signature name of the alert rules that address aspects of the same network vulnerability.

<attackCategory>

One of the following predefined attack categories:

  • Infection-Match—Alert rules that perform full or partial matching to identify a URL pointing to a Web infection.

  • Domain-Match - Alert rules that identify Bott IOC domain alerts.

  • Malware-Callback—Alert rules that identify callback events, which include signature matches and communications with a botnet server.

  • Riskware—Alert rules that identify files that are similar to malware but are not intended to be malicious.

  • IPS—All IPS alert rules.

  • Reconnaissance—IPS alert rules that detect reconnaissance activity (ping sweeps and port scans of ports, hosts, or networks) in progress and generate alerts when suspicious activity reaches a threshold.

  • Local-Signature—All custom alert rules, including custom IPS rules.

<portPair>

A monitoring port pair. See the Hardware Administration Guide for your appliance.

  • A—Port pair pether3 and pether4

  • B—Port pair pether5 and pether6

  • C—Port pair pether7 and pether8

  • D—Port pair pether9 and pether10

  • E—Port pair pether11 and pether12

  • F—Port pair pether13 and pether14

<srcIP>/<prefix>

A source host or subnet IPv4/IPv6 address in CIDR format.

If this parameter is not specified, the exception matches any source address.

<dstIP>/<prefix>

A destination host or subnet IPv4/IPv6 address in CIDR format.

If this parameter is not specified, the exception matches any destination address.

<actionType>

An override action as described in Alert policy exception actions :

block , default-action, suppress, suppress-unblock, or unblock.

Prerequisites

  • Admin or Operator access to the appliance.

To configure an alert policy exception:
  1. Go to configure mode.

    hostname > enable
    hostname # configure terminal
  2. View the list of alert policy exceptions.

    hostname (config) # show policymgr signatures
  3. Configure an alert policy exception.

    To configure an exception for a single alert rule, specify the eight-digit rule ID <sigID> by using the following form of the command:

    policymgr signature id <sigID> interface {<portPair> | ALL | MGMT}
    src {<srcIP>/<prefix> | any | any-v6} dst {<dstIP>/<prefix> | any | any-v6} action <actionType>

    To configure an exception for the alert rules that address aspects of the same network vulnerability, specify the vulnerability name <sigName> by using the following form of the command:

    policymgr signature name <sigName> interface {<portPair> | ALL | MGMT}
    src {<srcIP>/<prefix> | any | any-v6} dst {<dstIP>/<prefix> | any | any-v6} action <actionType>

    To configure an exception for the alert rules that belong to the same predefined category, specify the attack category by using the following form of the command:

    policymgr signature category <attackCategory> interface {<portPair> | ALL | MGMT}
    src {<srcIP>/<prefix> | any | any-v6} dst {<dstIP>/<prefix> | any | any-v6} action <actionType>

    To configure an exception for all signatures, use the following form of the command:

    policymgr signature name all interface {<portPair> | ALL | MGMT}
    src {<srcIP>/<prefix> | any | any-v6} dst {<dstIP>/<prefix> | any | any-v6} action <actionType>

    The following example configures the alert policy exceptions displayed in the example in Viewing the list of alert policy exceptions using the CLI.

    policymgr signature all interface A src 10.128.30.0/24 dst any action suppress
    policymgr signature id 93000001 interface A src 10.128.45.154/32 dst 172.217.27.36/32 action unblock
    policymgr signature id 93000002 interface A src 10.128.45.154/32 dst 172.217.27.36/32 action block
    policymgr signature category IPS interface B src 10.128.30.0/24 dst any action suppress-unblock
    policymgr signature name google interface all src any dst any action default-action
  4. Check your changes.

    hostname (config) # show policymgr signatures
  5. Save your changes

    hostname (config) # write memory