The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create/Update Light Weight Policy

Prev Next

This URL creates/updates a light weight policy for a specific interface or sub interface.

Resource URL

POST /sensor/<sensor_id>/interface/<interface_id or subinterface_id>/localipspolicy

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

sensor_id

Sensor Id

Number

Yes

interface_id or subinterface_id

Unique interface/sub interface id

Number

Yes

Payload Parameters:

Field Name

Description

Data Type

Mandatory

PolicyDescriptor

Baseline IPS policy details

Object

Yes

Details of PolicyDescriptor:

Field Name

Description

Data Type

Mandatory

PolicyName

Baseline IPS policy name

String

Yes

Description

Policy description

String

Yes

IsVisibleToChildren

Is policy visible to child domain

Boolean

Yes

InboundRuleSet

Inbound policy rule set

String

Yes

OutboundRuleSet

Outbound policy rule set

String

Yes

AttackCategory

Attack category

Object

Yes

OutboundAttackCategory

Outbound attack category

Object

Yes

DosPolicy

DoS policy

Object

Yes

ReconPolicy

Recon policy

Object

Yes

DosResponseSensitivityLevel

DoS response sensitivity level

Number

Yes

IsEditable

Is policy editable

Boolean

Yes

Timestamp

Time stamp at which the policy was added

String

Yes

VersionNum

Policy version number

Number

Yes

IsLightWeightPolicy

Is light weight policy configured

Boolean

Yes

Details of object in AttackCategory:

Field Name

Description

Data Type

Mandatory

ExpolitAttackList

List of exploit attacks

Array

Yes

Details of object in ExpolitAttackList:

Field Name

Description

Data Type

Mandatory

attackName

Attack name

String

Yes

nspId

NSP ID of the attack

String

Yes

severity

Attack severity, number between 0 & 9

Number

Yes

isSeverityCustomized

Is attack severity customized

Boolean

Yes

isEnabled

Is attack enabled

Boolean

Yes

isAlertCustomized

Is alert customized

Boolean

Yes

isRecommendedForSmartBlocking

Is attack recommended for smart blocking

Boolean

Yes

AttackResponse

Attack response

Object

Yes

notification

Notifications configured

Object

Yes

protocolList

List of protocols

Array

Yes

applicationsImpactedList

List of applications impacted

Array

Yes

attackVector

List of attack vectors

Array

Yes

benignTriggerProbability

Attack benign trigger probability

String

Yes

target

Attack target, can be "Server" or "Client"

String

Yes

blockingType

Blocking type, can be "Attack Packet"

String

Yes

subCategory

Attack sub category

String

Yes

direction

Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH"

String

Yes

isAttackCustomized

Is attack customized

Boolean

Yes

Details of object in AttackResponse:

Field Name

Description

Data Type

Mandatory

TCPReset

TCP reset option, can be “DISABLED” / “SOURCE” / “DESTINATION” / “BOTH”

String

Yes

isTCPResetCustomized

Is TCP reset customized

Boolean

Yes

isICMPSend

Send ICMP host unreachable to Source

Boolean

Yes

isICMPSendCustomized

Send ICMP host unreachable to Source customized

Boolean

Yes

mcafeeNACNotification

NAC notification configured, can be “DISABLED” / “ALL_HOSTS” / “MCAFEE_NAC_UNMANAGED_HOSTS”

String

Yes

isMcafeeNACNotificationEnabled

Is NAC notification enabled

Boolean

Yes

isQuarantineCustomized

Is quarantine customized

Boolean

Yes

isRemediateEnabled

Is remediate enabled

Boolean

Yes

blockingOption

Blocking option configured, can be “DISABLE” / “ENABLE” / “ENABLE_SMART_BLOCKING”

String

Yes

isBlockingOptionCustomized

Is blocking option customized

Boolean

Yes

isCapturedPrior

Should application data be captured prior to attack

Boolean

Yes

isCapturedPriorCustomized

Should application data be captured prior to attack customized

Boolean

Yes

action

Action to be taken on attack, can be “DO_NOTHING” / “SEND_ALERT_AND_LOG_PACKETS” / “SEND_ALERT_ONLY”

String

Yes

isLogCustomized

Is logging customized

Boolean

Yes

flow

Customixe flow, can be “SINGLE_FLOW” / “FORENSIC_ANALYSIS”

String

Yes

isFlowCustomized

Customize flow type

Boolean

Yes

isNbytesCustomized

Is logging N bytes in each packet customized

Boolean

Yes

numberOfBytesInEachPacket

Number of bytes to be logged in each packet

Object

Yes

loggingDuration

Packet logging duration

Object

Yes

TimeStamp

Time stamp

String

Yes

Details of object in numberOfBytesInEachPacket (Can be either of the below mentioned):

Field Name

Description

Data Type

Mandatory

LogEntirePacket

Log entire packet

Object

Yes

CaptureNBytes

Capture N bytes

Object

Yes

Details of object in CaptureNBytes:

Field Name

Description

Data Type

Mandatory

NumberOfBytes

Number of bytes to log

Number

Yes

Details of object in loggingDuration (Can be either of the below mentioned):

Field Name

Description

Data Type

Mandatory

AttackPacketOnly

Log attack packet only

Object

Yes

CaptureNPackets

Capture N packets

Object

Yes

CaptureTimeDuration

Capture for a time duration

Object

Yes

RestOfFlow

Capture rest of flow

Object

Yes

Details of object in CaptureNPackets:

Field Name

Description

Data Type

Mandatory

npackets

Log n packets

Number

Yes

Details of object in CaptureTimeDuration:

Field Name

Description

Data Type

Mandatory

time

Capture time

String

Yes

timeUnit

Time unit, can be "SECONDS" / "MINUTES" / "HOURS" / "DAYS"

String

Yes

Details of object in notification:

Field Name

Description

Data Type

Mandatory

isEmail

Is notification configured through email

Boolean

Yes

isPager

Is notification configured through pager

Boolean

Yes

isScript

Is notification configured through script

Boolean

Yes

isAutoAck

Is notification configured through auto ack

Boolean

Yes

isSnmp

Is notification configured through SNMP

Boolean

Yes

isSyslog

Is notification configured through Syslog

Boolean

Yes

isEmailCustomized

Is notification through Email customized

Boolean

Yes

isPagerCustomized

Is notification through Pager customized

Boolean

Yes

isScriptCustomized

Is notification through Script customized

Boolean

Yes

isAutoAckCustomized

Is notification through Auto Ack customized

Boolean

Yes

isSnmpCustomized

Is notification through SNMP customized

Boolean

Yes

isSyslogCustomized

Is notification through Syslog customized

Boolean

Yes

Details of object in DosPolicy:

Field Name

Description

Data Type

Mandatory

LearningAttack

List of learning attacks

Array

Yes

ThresholdAttack

List of threshold attacks

Array

Yes

TimeStamp

Time stamp

String

Yes

Details of object in LearningAttack:

Field Name

Description

Data Type

Mandatory

attackName

Attack name

String

Yes

nspId

NSP id of the attack

String

Yes

isSeverityCustomized

Is attack severity customized

Boolean

Yes

severity

Attack severity, number between 0 & 9

Number

Yes

isBlockingSettingCustomized

Is blocking customized

Boolean

Yes

isDropPacket

Drop DoS attack packets of this attack type when detected

Boolean

Yes

isAlertCustomized

Is alert customized

Boolean

Yes

isSendAlertToManager

Is alert notification to be sent to Manager configured

String

Yes

timeStamp

Time stamp

String

Yes

direction

Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH"

String

Yes

notification

Notification to be sent

Object

Yes

isAttackCustomized

Is DoS learning attack customized

Boolean

Yes

Details of object in ThresholdAttack:

Field Name

Description

Data Type

Mandatory

attackName

Attack name

String

Yes

nspId

NSP id of the attack

String

Yes

isSeverityCustomized

Is attack severity customized

Boolean

Yes

severity

Attack severity, number between 0 & 9

Number

Yes

isThresholdValueCustomized

Is threshold value customized

Boolean

Yes

isThresholdDurationCustomized

is threshold duration customized

Boolean

Yes

ThresholdValue

Threshold values

Number

Yes

ThresholdDuration

Threshold interval (Seconds)

Number

Yes

isAlertCustomized

Is alert customized

Boolean

Yes

isSendAlertToManager

Is alert notification to be sent to Manager configured

String

Yes

TimeStamp

Time stamp

String

Yes

Notification

Notification to be sent via

Object

Yes

direction

Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH"

String

Yes

isAttackCustomized

Is DoS threshold attack customized

Boolean

Yes

Details of object in ReconPolicy:

Field Name

Description

Data Type

Mandatory

ReconAttackList

List of recon attacks

Array

Yes

TimeStamp

Time stamp

String

Yes

attackName

Attack name

String

yes

nspId

NSP id of the attack

String

Yes

isSeverityCustomized

Is attack severity customized

Boolean

Yes

severity

Severity, number between 0 & 9

Number

Yes

isThresholdValueCustomized

Is threshold value customized

Boolean

Yes

Is Threshold valuecustomized

is threshold duration customized

Boolean

Yes

ThresholdValue

Threshold values

Number

Yes

ThresholdDuration

Threshold interval (seconds)

Number

Yes

mcAfeeNACNotification

Configured NAC notification that can be

"DISABLED" / "ALL_HOSTS" /

"MCAFEE_NAC_UNMANAGED_HOSTS"

String

Yes

isMcAfeeNACNotificationEnable

Is NAC notification enabled

Boolean

Yes

isQuarantineCustomized

Is quarantine customized

Boolean

Yes

isRemediateEnabled

is remediate enabled

Boolean

Yes

isAlertSuppressionTimerCustom

Is alert suppression customized

Boolean

Yes

alertSuppressionTimer

Alert suppression timer

Number

Yes

IsAlertCustomized

Is alert customized

Boolean

Yes

isSendAlertToManager

Is alert notification to be sent to Manager configured

String

Yes

timestamp

Time stamp

String

Yes

direction

Attack direction that can be "INBOUND" /

"OUTBOUND" / "BOTH"

String

Yes

notification

Notification to be sent via

Object

Yes

isAttackCustomized

Is recon attack customized

Boolean

Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

createdResourceId

Unique id of the light weight policy

Number

Example

Request

POST https://<NSM_IP>/sdkapi/sensor/1001/interface/105/localipspolicy

Payload:

{
    "PolicyDescriptor":
    {
        "IsVisibleToChildren": true,
        "InboundRuleSet": "testRuleSet",
        "OutboundRuleSet": "Null",
        "AttackCategory":
       {
           "ExpolitAttackList":
           [
               {
                   "attackName": "IDENT: TinyIdentD Identification Protocol Request Handling Remote Stack Overflow",
                   "nspId": "0x42700e00",
                   "severity": 6,
                   "isSeverityCustomized": true,
                   "isEnabled": true,
                   "isAlertCustomized": false,
                   "isRecommendedForSmartBlocking": false,
                   "AttackResponse":
                   {
                       "TCPReset": "DISABLED",
                       "isTcpResetCustomized": false,
                       "isICMPSend": false,
                       "isICMPSendCustomized": false,
                       "mcAfeeNACNotification": "DISABLED",
                       "isMcAfeeNACNotificationEnabled": false,
                       "isQuarantineCustomized": false,
                       "isRemediateEnabled": false,
                       "blockingOption": "DISABLE",
                       "isBlockingOptionCustomized": false,
                       "isCapturedPrior": true,
                       "isCapturedPriorCustomized": false,
                       "action": "SEND_ALERT_ONLY",
                       "isLogCustomized": false,
                       "isFlowCustomized": false,
                       "isNbytesCustomized": false,
                       "numberOfBytesInEachPacket":
                       {
                           "LogEntirePacket":
                           {
                           }
                       }
                   },
                   "notification":
                   {
                       "isEmail": false,
                       "isPager": false,
                       "isScript": false,
                       "isAutoAck": false,
                       "isSnmp": false,
                       "isSyslog": false,
                       "isEmailCustomized": false,
                       "isPagerCustomized": false,
                       "isScriptCustomized": false,
                       "isAutoAckCustomized": false,
                       "isSnmpCustomized": false,
                       "isSyslogCustomized": false
                   },
                   "protocolList":
                   [
                       "ident"
                   ],
                   "benignTriggerProbability": "3 (Medium)",
                   "blockingType": "attack-packet",
                   "subCategory": "buffer-overflow",
                   "direction": "INBOUND",
                   "isAttackCustomized": true
               }
           ]
       },
       "OutboundAttackCategory":
       {
       },
       "DosPolicy":
       {
           "LearningAttack":
           [
                {
                    "attackName": "Outbound ICMP Echo Request or Reply Volume Too High",
                    "nspId": "0x40018000",
                    "isSeverityCustomized": false,
                    "severity": 7,
                    "isBlockingSettingCustomized": false,
                    "isDropPacket": false,
                    "IsAlertCustomized": false,
                    "isSendAlertToManager": true,
                    "direction": "OUTBOUND",
                    "notification":
                    {
                        "isEmail": false,
                        "isPager": false,
                        "isScript": false,
                        "isAutoAck": false,
                        "isSnmp": false,
                        "isSyslog": false,
                        "isEmailCustomized": false,
                        "isPagerCustomized": false,
                        "isScriptCustomized": false,
                        "isAutoAckCustomized": false,
                        "isSnmpCustomized": false,
                        "isSyslogCustomized": false
                    },
                    "isAttackCustomized": false
                }
            ],
            "ThresholdAttack":
            [
                {
                    "attackName": "Too Many Outbound IP Fragments",
                    "nspId": "0x40018800",
                    "isSeverityCustomized": false,
                    "severity": 6,
                    "isThresholdValueCustomized": false,
                    "isThresholdDurationCustomized": false,
                    "ThresholdValue": 1000,
                    "ThresholdDuration": 5,
                    "isAlertCustomized": false,
                    "isSendAlertToManager": false,
                    "Notification":
                    {
                        "isEmail": false,
                        "isPager": false,
                        "isScript": false,
                        "isAutoAck": false,
                        "isSnmp": false,
                        "isSyslog": false,
                        "isEmailCustomized": false,
                        "isPagerCustomized": false,
                        "isScriptCustomized": false,
                        "isAutoAckCustomized": false,
                        "isSnmpCustomized": false,
                        "isSyslogCustomized": false
                    },
                    "direction": "OUTBOUND",
                    "isAttackCustomized": false
                }
            ],
            "TimeStamp": "2012-08-31 15:20:54.000"
        },
        'ReconPolicy': {
														'TimeStamp': None,
														'ReconAttackList': [{
																					'IsAlertCustomized': False,
																					'isSeverityCustomized': False,
																					'direction': None,
																					'severity': 5,
																					'isThresholdDurationCustomized': False,
																					'isSendAlertToManager': False,
																					'isQuarantineCustomized': False,
																					'attackName': 'BOTHeuristic: PotentialBotActivity-
MultipleResetsfromSMTPreceiver',
																					'ThresholdDuration': 0,
																					'alertSuppressionTimer': 0,
																					'isAlertSuppressionTimerCustomized': False,
																					'isAttackCustomized': False,
																					'isMcAfeeNACNotificationEnabled': False,
																					'isThresholdValueCustomized': False,
																					'nspId': '0x43f00900',
																					'mcAfeeNACNotification': 'DISABLED',
																					'isRemediateEnabled': False,
																					'timeStamp': None,
																					'ThresholdValue': 0,
																					'notification': {
																												'isSnmp': False,
																												'isAutoAckCustomized': False,
																												'isPagerCustomized': False,
																												'isSyslogCustomized': False,
																												'isEmail': False,
																												'isSyslog': False,
																												'isScriptCustomized': False,
																												'isSnmpCustomized': False,
																												'isScript': False,
																												'isPager': False,
																												'isEmailCustomized': False,
																												'isAutoAck': False
																					}
												}]
},
        "DosResponseSensitivityLevel": 0,
        "IsEditable": false,
								"Timestamp": "2012-08-31 15:20:55.000",
								"VersionNum": 1, 
								"IsLightWeightPolicy": true
    }
}

Response

{
"createdResourceId":105
}

Error Information

Following error codes are returned by this URL:

S.No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

404

1106

Invalid Sensor

2

404

1107

Invalid interface or sub-interface id

3

400

1301

The number of attacks does not match the number in the baseline policy

4

400

1302

Number of bytes has to be between 1 to 255

5

400

1303

Please provide the number of bytes to be logged

6

400

1304

Please provide duration of logging for flow

7

400

1305

Number of bytes has to be between 2 to 255

8

400

1306

Time has to be between 1 to 63

9

400

1307

Please provide a time

10

400

1308

Please provide a time interval

11

400

1309

Please provide the flow

12

400

1310

Invalid severity - please provide a value between 0 and 10

13

400

1311

Invalid threshold value - please enter a value between 1 and 2147483647

14

400

1312

Invalid threshold duration - please enter a value between 1 and 2147483647