The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring an IPS policy using a CMC profile (CLI)

Prev Next

From the Central Management System appliance CLI, you can use a central management console (CMC) profile to configure a custom IPS policy on managed IPS-enabled platforms in the centralized management domain. You can configure the custom IPS policy on a single managed IPS-enabled platform, or you can configure the policy on a group of managed platforms.

Prerequisites
  • Log in to the CLI of the Central Management System appliance as Operator or Admin.

Procedure
To configure a custom IPS policy on a managed IPS-enabled platform:
  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Configure the first command of the CMC profile to create a custom IPS policy.

    The following example configures profile c1 to create a custom IPS policy named p1.

    hostname (config) # cmc profile c1 comment "IPS policy for IPS-ena NX platforms"
    hostname (config) # cmc profile c1 command 1 "ips policy p1"
  3. Configure the profile to specify required match attributes for the custom IPS policy.

    The following example configures the attributeds attack‑target, min‑severity, and max‑severity.

    hostname (config) # cmc profile c1 command 2 "ips policy p1 match attack-target client"
    hostname (config) # cmc profile c1 command 3 "ips policy p1 match min-severity 8"
    hostname (config) # cmc profile c1 command 4 "ips policy p1 match max-severity 10"
  4. (Optional) Configure the profile to specify optional match attributes for the custom IPS policy.

    The following example configures an optional protocol attribute.

    hostname (config) # cmc profile c1 command 5 "ips policy p1 match protocol SNMP"
  5. (Optional) Configure the profile to specify optional rule exclusion or inclusion attributes for the custom IPS policy.

    The following example configures the optional attributes rules exclude and rules include.

    hostname (config) # cmc profile c1 command 6 "ips policy p1 rules exclude 85300001"
    hostname (config) # cmc profile c1 command 7 "ips policy p1 rules include 85300002"
    hostname (config) # cmc profile c1 command 8 "ips policy p1 rules include 85300003"
  6. Before you save the CMC profile to managed IPS-enabled platforms, list the CLI commands and comments in the profile.

    The following example step lists the CLI commands in the profile c1.

    hostname (config) # show cmc profile c1
    Profile c1
       Comment:             IPS policy for IPS-ena NX platforms
       Commands:
          1. ips policy p1
          2. ips policy p1 match attack-target client
          3. ips policy p1 match min-severity 8
          4. ips policy p1 match max-severity 10
          5. ips policy p1 match protocol SNMP
          6. ips policy p1 rules exclude 85300001
          7. ips policy p1 rules include 85300002
          8. ips policy p1 rules include 85300003

    Note

    To delete a command from the profile, use the no cmc profile name command and specify the command sequence_number option.

    The following example deletes the eighth command from the profile:

    hostname (config) # no cmc profile c1 command 8
  7. Apply the profile to a single managed IPS-enabled platform or to a group of appliances.

    • To apply the profile to a single managed appliance, use the cmc profile

      name

      command and specify the apply appliance

      name

      option.

      The following example step applies the profile to the appliance NX_4400_IPS.

      hostname (config) # cmc profile c1 apply appliance NX_4400_IPS
      ============ Appliance NX_4400_IPS ============
      Execution was successful.
      Execution output:
      Saving configuration file ... Done!
      

      The configuration for the managed appliance NX_4400_IPS includes the definition of the custom IPS profile p1.

    • To apply the profile to a group of managed appliances, use the cmc profile

      name

      command and specify the apply group

      name

      option.

      The following example step applies the profile to the appliances in the group NXips, which is composed of IPS-enabled appliances named NX_900_IPS and NX_10000_IPS.

      hostname (config) # cmc profile c1 apply group NXips
      ============ Appliance NX_900_IPS ============
      Execution was successful.
      Execution output:
      Saving configuration file ... Done!
      ============ Appliance NX_10000_IPS ============
      Execution was successful.
      Execution output:
      Saving configuration file ... Done!
      

      The configurations for the managed appliances in group NXips include the definition of the custom IPS profile p1.

  8. Save your changes.

    hostname (config) # write memory