The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Deleting a custom IPS policy (CLI)

Prev Next

You can use CLI commands to delete a custom IPS policy definition from an IPS platform.

Prerequisites
  • Log in to the CLI of the IPS platform as Operator or Admin.

  • Make sure that the IPS policy is not applied to any monitoring interfaces.

    • Use the show ips policies command to check whether the policy is active.

    • If the policy you want to delete is active, use the show ips interfaces command to display the interface to which the policy is applied, and then use the no ips apply command to remove the policy from an interface.

To delete a custom IPS policy definition from the platform:
  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. List the IPS policies defined on the platform.

    Note

    You cannot delete an IPS policy while it is applied to an interface.

    hostname # show ips policies
    FireEye_Default
            active : yes
            version : 2
    Comprehensive
            active : no
            version : 2
    Default_Server_Protection
            active : no
            version : 2
    Default_Client_Protection
            active : no
            version : 2
    myCustom1
            active : no
            version : 1
            No. of included rules: 1
            No. of excluded rules: 2
    myCustom2
            active : no
            version : 1
            No. of included rules: 1
            No. of excluded rules: 2
    myCustom3
            active : no
            version : 1
            No. of included rules: 1
            No. of excluded rules: 2
  3. Delete any custom IPS policy definitions from the platform.

    hostname (config) # no ips policy myCustom1
    hostname (config) # no ips policy myCustom2
    hostname (config) # no ips policy myCustom3
  4. Confirm your changes.

    hostname (config) # show ips policies ?
    <cr>
    <Policy name>
    FireEye_Default
    Comprehensive
    Default_Server_Protection
    Default_Client_Protection
  5. Save your changes.

    hostname (config) # write memory