The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Disabling IPS detection of brute-force attacks (Web UI)

Prev Next

IPS detection of brute-force attacks is enabled by default. If you want to disable brute-force detection, the feature is not disabled globally. Instead, you can disable the brute-force detection rules for an IPS policy. Edit the custom IPS policy and disable all IPS rules that detect brute-force attacks.

Prerequisites
Procedure

To disable detection of brute-force attacks:

  1. Choose IPS > Configure.

  2. Find the IPS policy for which you want to disable brute-force attacks.

  3. Go to the Actions column and click Edit or Clone & Edit.

  4. Click the search icon (ctrl_ips_IPS_Events_search.png) in the Category heading.

  5. In the text box below the Category heading, type brute and then press Enter.

    scap_ips_settings_ips_policy-editor_bf.png

  6. Use the check boxes ( ctrl_ips_select.png ) in the Enabled column to specify which IPS brute-force rules are enforced.

    • Clear all options to disable the rules.

    • Select all options to enable the rules.

    • Select only the options for IPS brute-force rules you want to apply.

  7. Click Save Policy.

  8. If the New Policy Name window appears, enter a name for the new policy and then click Save Policy.

  9. Select the monitoring interface to which you want to apply the policy.

  10. Click Apply.