You can use CLI commands to delete a custom IPS policy definition from an IPS platform.
Prerequisites
Log in to the CLI of the IPS platform as Operator or Admin.
Make sure that the IPS policy is not applied to any monitoring interfaces.
Use the
show ips policiescommand to check whether the policy is active.If the policy you want to delete is active, use the show ips interfaces command to display the interface to which the policy is applied, and then use the no ips apply command to remove the policy from an interface.
Enable the CLI configuration mode.
hostname > enable hostname # configure terminal
List the IPS policies defined on the platform.
Note
You cannot delete an IPS policy while it is applied to an interface.
hostname # show ips policies FireEye_Default active : yes version : 2 Comprehensive active : no version : 2 Default_Server_Protection active : no version : 2 Default_Client_Protection active : no version : 2 myCustom1 active : no version : 1 No. of included rules: 1 No. of excluded rules: 2 myCustom2 active : no version : 1 No. of included rules: 1 No. of excluded rules: 2 myCustom3 active : no version : 1 No. of included rules: 1 No. of excluded rules: 2Delete any custom IPS policy definitions from the platform.
hostname (config) # no ips policy myCustom1 hostname (config) # no ips policy myCustom2 hostname (config) # no ips policy myCustom3
Confirm your changes.
hostname (config) # show ips policies ? <cr> <Policy name> FireEye_Default Comprehensive Default_Server_Protection Default_Client_ProtectionSave your changes.
hostname (config) # write memory