Once you're up and running and reviewing the data generated by the Manager, you can further configure it. For example, you can do the following:
Apply security policies to each interface of your multi-port Sensor (instead of the Default Inline IPS policy applied to all interfaces): You can ensure all of your interfaces deploy policies specifically for the areas of your network they are monitoring. For example, you can apply the Web Server policy to one interface, the Mail Server policy to another, and the Internal Segment policy to another, and so on. For more on the policies, see the section Trellix IPS policies.
Configure responses to alerts: Developing a system of actions, alerts, and logs based on impact severity is recommended for effective network security. For example, you can configure Trellix IPS to send a page or an email notification, execute a script, disconnect a TCP connection, send an ICMP Host Not Reachable message to the attack source for ICMP transmissions, or send a block address filter to a host.
For information on response actions, see the section Sensor response actions.
For information on configuring a pager, email, or script notification for alerts, see the section Alert notification options.
For information on configuring a quarantine response, see the section Quarantining hosts.
You can also send SNMP traps to a third-party management system. For more details, see the sections Forward alerts to an SNMP server, and Forward faults to an SNMP server .
Filter alerts: An ignore rule limits the number of alerts generated by the system by excluding certain source and Destination IP address parameters. If these address parameters are detected in a packet, the packet is not analyzed further (and is automatically forwarded when in Inline Mode). For more information on ignore rules, see Trellix Intrusion Prevention System Product Guide.
View the system's health: The Faults tab in the Logs page details the functional status for all of your installed Trellix IPSsystem components. Messages are generated to detail system faults experienced by your Manager, Sensors, or database. For more information, see the Manager Administration section.
View a Sensor's performance: The Devices → <Admin Domain Name> → Global → Common Device Settings → Performance Monitoring → Summary action enables you to view performance data for a Sensor. The data collected is a reflection of the traffic that has passed through the Sensor. For more information, see Manager Administration section.
Back up all or part of your Manager configuration information to your server or other location. For more information, see the section Backing up data and settings.