The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Customize IPS Policy

Prev Next

You can customize this IPS policy only for this interface. Such a customized IPS policy is referred to as the Interface-Specific Customization. The initial attack settings are inherited from the assigned policy, yet customization to the policy affect this interface only.

  1. Click the Policy tab.

  2. Select the domain from the Domain drop-down list.

  3. Navigate to Intrusion Prevention → Policy Manager → Interfaces.

  4. Double-click on the interface for which you want to customize the policy.

    The <Device Name/Interface> panel opens on the right side.

  5. Under the IPS section, select the policy from the Policy drop-down list that you want to assign to the interface.

  6. Click on 0 next to the Customized Attacks field under Interface-Specific Customization.

    The Attack Definitions window opens.

  7. Select the policy you want to disable for the interface and click Disable one by one.

    To disable multiple policies at once, use the Ctrl key to select the policies and then click Disable.

    Note

    All the attacks are enabled by default.

    Attack Definitions page
    Attack Definitions page


  8. Click Save to save the changes.

    A Save Confirmation window opens. Click Confirm to save the changes.

    Confirmation message
    Confirmation message


    Click the X icon to exit the window without saving the changes.

  9. Click the Save button in the <Device Name/Interface> panel to save all the changes.

    The Customized Attacks field shows the integer value of the number of attacks customized for that policy.

  10. Click the GUID-40B39B82-4DBB-4F98-8226-A6C73B926326-low.png icon to merge the customized policy with the assigned policy.

    A confirmation message is displayed. Click Yes to confirm.

    Customized attacks merge
    Customized attacks merge


  11. After a successful merge, the Customized Attacks field shows the value as "0".

    Note

    You can customize the IPS policy in both the interface and subinterface levels.

  12. Click the GUID-377572A5-33EB-43F9-A828-202101E436DC-low.png to delete any customization made to the policy, before merging it with the assigned policy.

    A confirmation message is displayed. Click Yes to confirm. The Customized Attacks field displays "0" as the integer value.

  13. Do a configuration update for the corresponding Sensor for the changes to take effect.