An advanced deployment of Trellix IPS utilizes more of its features to best tune your system. After you are more familiar with Trellix IPS, you might do the following:
- Try running in in-line mode. In-line mode enables you to drop malicious traffic and thus prevents attacks from ever reaching their targets.
- Split your deployment into multiple Admin Domains. You may want to organize your deployment by geographical location, business unit, or functional area (such as HR, Finance, etc).
- Segment your network traffic into VLAN tags and CIDR blocks. You can thus monitor various traffic with distinct policies using the sub-interfaces feature.
- Create (or clone) policies on a sub-interface basis. Create policies tuned for specific traffic flows within a network segment, and apply them on an extremely granular level.
- Define user roles. Delegate the day-to-day management of the IPS to specific individuals, providing each person with only enough access to the system to carry out his/her responsibilities.
- Define DoS policies. Configure DoS policies for specific hosts or a subset of your network.