The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Defining and using user-customizable blocking strategy to make self-adaptable IPS policies

Prev Next

Trellix IPS Manager offers a simplified and automated IPS policy management mechanism for blocking attacks. It enables the users to define and store one or more customizable rules for blocking attacks as per their network requirements during attack set profile configuration. When the same attack set profile is used in the IPS policy, the Manager automatically correlates the blocking criteria set by the user with the new and existing attack signatures. This enables IPS policies to automatically block attacks that match the user's blocking strategy and makes them self-adaptable to any new signature set release.

The automated blocking mechanism by IPS policies as per user-defined blocking strategy helps in the following ways:

  • It minimizes the need to manually edit the IPS policies for the blocking of attacks in which one had to manually look for attack definitions that match their blocking criteria, bulk edit them, and set the Block field under Sensor Actions to Enable Blocking.

  • As the attack set profile mapped to the IPS policy stores the user-defined blocking criteria for attacks, it is automatically applied to any new/modified attack definitions included in any signature set update that match the set criteria. This eliminates the requirement of repeated manual intervention and provides user-customizable and automated attack blocking mechanism that helps users maintain their network security posture.

Important

Automating the blocking of attacks as per user-defined blocking strategy is available in Manager and Central Manager version 11.1 Update 3 and above.