The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create/Update Light Weight Policy

Prev Next

This URL creates/updates a light weight policy for a specific interface or sub interface.

Resource URL

POST /sensor/<sensor_id>/interface/<interface_id or subinterface_id>/localipspolicy

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
sensor_id Sensor Id Number Yes
interface_id or subinterface_id Unique interface/sub interface id Number Yes

Payload Parameters:

Field Name Description Data Type Mandatory
PolicyDescriptor Baseline IPS policy details Object Yes

Details of PolicyDescriptor:

Field Name Description Data Type Mandatory
PolicyName Baseline IPS policy name String Yes
Description Policy description String Yes
IsVisibleToChildren Is policy visible to child domain Boolean Yes
InboundRuleSet Inbound policy rule set String Yes
OutboundRuleSet Outbound policy rule set String Yes
AttackCategory Attack category Object Yes
OutboundAttackCategory Outbound attack category Object Yes
DosPolicy DoS policy Object Yes
ReconPolicy Recon policy Object Yes
DosResponseSensitivityLevel DoS response sensitivity level Number Yes
IsEditable Is policy editable Boolean Yes
Timestamp Time stamp at which the policy was added String Yes
VersionNum Policy version number Number Yes
IsLightWeightPolicy Is light weight policy configured Boolean Yes

Details of object in AttackCategory:

Field Name Description Data Type Mandatory
ExpolitAttackList List of exploit attacks Array Yes

Details of object in ExpolitAttackList:

Field Name Description Data Type Mandatory
attackName Attack name String Yes
nspId NSP ID of the attack String Yes
severity Attack severity, number between 0 & 9 Number Yes
isSeverityCustomized Is attack severity customized Boolean Yes
isEnabled Is attack enabled Boolean Yes
isAlertCustomized Is alert customized Boolean Yes
isRecommendedForSmartBlocking Is attack recommended for smart blocking Boolean Yes
AttackResponse Attack response Object Yes
notification Notifications configured Object Yes
protocolList List of protocols Array Yes
applicationsImpactedList List of applications impacted Array Yes
attackVector List of attack vectors Array Yes
benignTriggerProbability Attack benign trigger probability String Yes
target Attack target, can be "Server" or "Client" String Yes
blockingType Blocking type, can be "Attack Packet" String Yes
subCategory Attack sub category String Yes
direction Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH" String Yes
isAttackCustomized Is attack customized Boolean Yes

Details of object in AttackResponse:

Field Name Description Data Type Mandatory
TCPReset TCP reset option, can be “DISABLED” / “SOURCE” / “DESTINATION” / “BOTH” String Yes
isTCPResetCustomized Is TCP reset customized Boolean Yes
isICMPSend Send ICMP host unreachable to Source Boolean Yes
isICMPSendCustomized Send ICMP host unreachable to Source customized Boolean Yes
mcafeeNACNotification NAC notification configured, can be “DISABLED” / “ALL_HOSTS” / “MCAFEE_NAC_UNMANAGED_HOSTS” String Yes
isMcafeeNACNotificationEnabled Is NAC notification enabled Boolean Yes
isQuarantineCustomized Is quarantine customized Boolean Yes
isRemediateEnabled Is remediate enabled Boolean Yes
blockingOption Blocking option configured, can be “DISABLE” / “ENABLE” / “ENABLE_SMART_BLOCKING” String Yes
isBlockingOptionCustomized Is blocking option customized Boolean Yes
isCapturedPrior Should application data be captured prior to attack Boolean Yes
isCapturedPriorCustomized Should application data be captured prior to attack customized Boolean Yes
action Action to be taken on attack, can be “DO_NOTHING” / “SEND_ALERT_AND_LOG_PACKETS” / “SEND_ALERT_ONLY” String Yes
isLogCustomized Is logging customized Boolean Yes
flow Customixe flow, can be “SINGLE_FLOW” / “FORENSIC_ANALYSIS” String Yes
isFlowCustomized Customize flow type Boolean Yes
isNbytesCustomized Is logging N bytes in each packet customized Boolean Yes
numberOfBytesInEachPacket Number of bytes to be logged in each packet Object Yes
loggingDuration Packet logging duration Object Yes
TimeStamp Time stamp String Yes

Details of object in numberOfBytesInEachPacket (Can be either of the below mentioned):

Field Name Description Data Type Mandatory
LogEntirePacket Log entire packet Object Yes
CaptureNBytes Capture N bytes Object Yes

Details of object in CaptureNBytes:

Field Name Description Data Type Mandatory
NumberOfBytes Number of bytes to log Number Yes

Details of object in loggingDuration (Can be either of the below mentioned):

Field Name Description Data Type Mandatory
AttackPacketOnly Log attack packet only Object Yes
CaptureNPackets Capture N packets Object Yes
CaptureTimeDuration Capture for a time duration Object Yes
RestOfFlow Capture rest of flow Object Yes

Details of object in CaptureNPackets:

Field Name Description Data Type Mandatory
npackets Log n packets Number Yes

Details of object in CaptureTimeDuration:

Field Name Description Data Type Mandatory
time Capture time String Yes
timeUnit Time unit, can be "SECONDS" / "MINUTES" / "HOURS" / "DAYS" String Yes

Details of object in notification:

Field Name Description Data Type Mandatory
isEmail Is notification configured through email Boolean Yes
isPager Is notification configured through pager Boolean Yes
isScript Is notification configured through script Boolean Yes
isAutoAck Is notification configured through auto ack Boolean Yes
isSnmp Is notification configured through SNMP Boolean Yes
isSyslog Is notification configured through Syslog Boolean Yes
isEmailCustomized Is notification through Email customized Boolean Yes
isPagerCustomized Is notification through Pager customized Boolean Yes
isScriptCustomized Is notification through Script customized Boolean Yes
isAutoAckCustomized Is notification through Auto Ack customized Boolean Yes
isSnmpCustomized Is notification through SNMP customized Boolean Yes
isSyslogCustomized Is notification through Syslog customized Boolean Yes

Details of object in DosPolicy:

Field Name Description Data Type Mandatory
LearningAttack List of learning attacks Array Yes
ThresholdAttack List of threshold attacks Array Yes
TimeStamp Time stamp String Yes

Details of object in LearningAttack:

Field Name Description Data Type Mandatory
attackName Attack name String Yes
nspId NSP id of the attack String Yes
isSeverityCustomized Is attack severity customized Boolean Yes
severity Attack severity, number between 0 & 9 Number Yes
isBlockingSettingCustomized Is blocking customized Boolean Yes
isDropPacket Drop DoS attack packets of this attack type when detected Boolean Yes
isAlertCustomized Is alert customized Boolean Yes
isSendAlertToManager Is alert notification to be sent to Manager configured String Yes
timeStamp Time stamp String Yes
direction Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH" String Yes
notification Notification to be sent Object Yes
isAttackCustomized Is DoS learning attack customized Boolean Yes

Details of object in ThresholdAttack:

Field Name Description Data Type Mandatory
attackName Attack name String Yes
nspId NSP id of the attack String Yes
isSeverityCustomized Is attack severity customized Boolean Yes
severity Attack severity, number between 0 & 9 Number Yes
isThresholdValueCustomized Is threshold value customized Boolean Yes
isThresholdDurationCustomized is threshold duration customized Boolean Yes
ThresholdValue Threshold values Number Yes
ThresholdDuration Threshold interval (Seconds) Number Yes
isAlertCustomized Is alert customized Boolean Yes
isSendAlertToManager Is alert notification to be sent to Manager configured String Yes
TimeStamp Time stamp String Yes
Notification Notification to be sent via Object Yes
direction Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH" String Yes
isAttackCustomized Is DoS threshold attack customized Boolean Yes

Details of object in ReconPolicy:

Field Name Description Data Type Mandatory
ReconAttackList List of recon attacks Array Yes
TimeStamp Time stamp String Yes
attackName Attack name String yes
nspId NSP id of the attack String Yes
isSeverityCustomized Is attack severity customized Boolean Yes
severity Severity, number between 0 & 9 Number Yes
isThresholdValueCustomized Is threshold value customized Boolean Yes
Is Threshold valuecustomized is threshold duration customized Boolean Yes
ThresholdValue Threshold values Number Yes
ThresholdDuration Threshold interval (seconds) Number Yes
mcAfeeNACNotification Configured NAC notification that can be

"DISABLED" / "ALL_HOSTS" /

"MCAFEE_NAC_UNMANAGED_HOSTS"

String Yes
isMcAfeeNACNotificationEnable Is NAC notification enabled Boolean Yes
isQuarantineCustomized Is quarantine customized Boolean Yes
isRemediateEnabled is remediate enabled Boolean Yes
isAlertSuppressionTimerCustom Is alert suppression customized Boolean Yes
alertSuppressionTimer Alert suppression timer Number Yes
IsAlertCustomized Is alert customized Boolean Yes
isSendAlertToManager Is alert notification to be sent to Manager configured String Yes
timestamp Time stamp String Yes
direction Attack direction that can be "INBOUND" /

"OUTBOUND" / "BOTH"

String Yes
notification Notification to be sent via Object Yes
isAttackCustomized Is recon attack customized Boolean Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
createdResourceId Unique id of the light weight policy Number

Example

Request

POST https://%3CNSM_IP%3E/sdkapi/sensor/1001/interface/105/localipspolicy

Payload:

{
    "PolicyDescriptor":
    {
        "IsVisibleToChildren": true,
        "InboundRuleSet": "testRuleSet",
        "OutboundRuleSet": "Null",
        "AttackCategory":
       {
           "ExpolitAttackList":
           [
               {
                   "attackName": "IDENT: TinyIdentD Identification Protocol Request Handling Remote Stack Overflow",
                   "nspId": "0x42700e00",
                   "severity": 6,
                   "isSeverityCustomized": true,
                   "isEnabled": true,
                   "isAlertCustomized": false,
                   "isRecommendedForSmartBlocking": false,
                   "AttackResponse":
                   {
                       "TCPReset": "DISABLED",
                       "isTcpResetCustomized": false,
                       "isICMPSend": false,
                       "isICMPSendCustomized": false,
                       "mcAfeeNACNotification": "DISABLED",
                       "isMcAfeeNACNotificationEnabled": false,
                       "isQuarantineCustomized": false,
                       "isRemediateEnabled": false,
                       "blockingOption": "DISABLE",
                       "isBlockingOptionCustomized": false,
                       "isCapturedPrior": true,
                       "isCapturedPriorCustomized": false,
                       "action": "SEND_ALERT_ONLY",
                       "isLogCustomized": false,
                       "isFlowCustomized": false,
                       "isNbytesCustomized": false,
                       "numberOfBytesInEachPacket":
                       {
                           "LogEntirePacket":
                           {
                           }
                       }
                   },
                   "notification":
                   {
                       "isEmail": false,
                       "isPager": false,
                       "isScript": false,
                       "isAutoAck": false,
                       "isSnmp": false,
                       "isSyslog": false,
                       "isEmailCustomized": false,
                       "isPagerCustomized": false,
                       "isScriptCustomized": false,
                       "isAutoAckCustomized": false,
                       "isSnmpCustomized": false,
                       "isSyslogCustomized": false
                   },
                   "protocolList":
                   [
                       "ident"
                   ],
                   "benignTriggerProbability": "3 (Medium)",
                   "blockingType": "attack-packet",
                   "subCategory": "buffer-overflow",
                   "direction": "INBOUND",
                   "isAttackCustomized": true
               }
           ]
       },
       "OutboundAttackCategory":
       {
       },
       "DosPolicy":
       {
           "LearningAttack":
           [
                {
                    "attackName": "Outbound ICMP Echo Request or Reply Volume Too High",
                    "nspId": "0x40018000",
                    "isSeverityCustomized": false,
                    "severity": 7,
                    "isBlockingSettingCustomized": false,
                    "isDropPacket": false,
                    "IsAlertCustomized": false,
                    "isSendAlertToManager": true,
                    "direction": "OUTBOUND",
                    "notification":
                    {
                        "isEmail": false,
                        "isPager": false,
                        "isScript": false,
                        "isAutoAck": false,
                        "isSnmp": false,
                        "isSyslog": false,
                        "isEmailCustomized": false,
                        "isPagerCustomized": false,
                        "isScriptCustomized": false,
                        "isAutoAckCustomized": false,
                        "isSnmpCustomized": false,
                        "isSyslogCustomized": false
                    },
                    "isAttackCustomized": false
                }
            ],
            "ThresholdAttack":
            [
                {
                    "attackName": "Too Many Outbound IP Fragments",
                    "nspId": "0x40018800",
                    "isSeverityCustomized": false,
                    "severity": 6,
                    "isThresholdValueCustomized": false,
                    "isThresholdDurationCustomized": false,
                    "ThresholdValue": 1000,
                    "ThresholdDuration": 5,
                    "isAlertCustomized": false,
                    "isSendAlertToManager": false,
                    "Notification":
                    {
                        "isEmail": false,
                        "isPager": false,
                        "isScript": false,
                        "isAutoAck": false,
                        "isSnmp": false,
                        "isSyslog": false,
                        "isEmailCustomized": false,
                        "isPagerCustomized": false,
                        "isScriptCustomized": false,
                        "isAutoAckCustomized": false,
                        "isSnmpCustomized": false,
                        "isSyslogCustomized": false
                    },
                    "direction": "OUTBOUND",
                    "isAttackCustomized": false
                }
            ],
            "TimeStamp": "2012-08-31 15:20:54.000"
        },
        'ReconPolicy': {
														'TimeStamp': None,
														'ReconAttackList': [{
																					'IsAlertCustomized': False,
																					'isSeverityCustomized': False,
																					'direction': None,
																					'severity': 5,
																					'isThresholdDurationCustomized': False,
																					'isSendAlertToManager': False,
																					'isQuarantineCustomized': False,
																					'attackName': 'BOTHeuristic: PotentialBotActivity-
MultipleResetsfromSMTPreceiver',
																					'ThresholdDuration': 0,
																					'alertSuppressionTimer': 0,
																					'isAlertSuppressionTimerCustomized': False,
																					'isAttackCustomized': False,
																					'isMcAfeeNACNotificationEnabled': False,
																					'isThresholdValueCustomized': False,
																					'nspId': '0x43f00900',
																					'mcAfeeNACNotification': 'DISABLED',
																					'isRemediateEnabled': False,
																					'timeStamp': None,
																					'ThresholdValue': 0,
																					'notification': {
																												'isSnmp': False,
																												'isAutoAckCustomized': False,
																												'isPagerCustomized': False,
																												'isSyslogCustomized': False,
																												'isEmail': False,
																												'isSyslog': False,
																												'isScriptCustomized': False,
																												'isSnmpCustomized': False,
																												'isScript': False,
																												'isPager': False,
																												'isEmailCustomized': False,
																												'isAutoAck': False
																					}
												}]
},
        "DosResponseSensitivityLevel": 0,
        "IsEditable": false,
								"Timestamp": "2012-08-31 15:20:55.000",
								"VersionNum": 1, 
								"IsLightWeightPolicy": true
    }
} 

Response

{
"createdResourceId":105
} 
 

Error Information

Following error codes are returned by this URL:

S.No HTTP Error Code SDK API errorId SDK API errorMessage
1 404 1106 Invalid Sensor
2 404 1107 Invalid interface or sub-interface id
3 400 1301 The number of attacks does not match the number in the baseline policy
4 400 1302 Number of bytes has to be between 1 to 255
5 400 1303 Please provide the number of bytes to be logged
6 400 1304 Please provide duration of logging for flow
7 400 1305 Number of bytes has to be between 2 to 255
8 400 1306 Time has to be between 1 to 63
9 400 1307 Please provide a time
10 400 1308 Please provide a time interval
11 400 1309 Please provide the flow
12 400 1310 Invalid severity - please provide a value between 0 and 10
13 400 1311 Invalid threshold value - please enter a value between 1 and 2147483647
14 400 1312 Invalid threshold duration - please enter a value between 1 and 2147483647