Using the CLI, you can edit the rule match, rule inclusion, and rule exclusion attributes of a policy:
Editing the rule match attributes of an IPS policy (CLI)
Editing the rule inclusion and exclusion attributes of an IPS policy (CLI)
To override the actions specified by rules selected by an IPS policy, you must use the Web UI.
Note
You cannot edit a default IPS policy, but you can edit a clone of a default IPS policy. See Cloning an IPS policy (CLI).
Editing the rule match attributes of an IPS policy (CLI)
You can add, change, or remove the match attributes of a custom IPS policy only. For a description of all attributes of an IPS policy, see Attributes of IPS policies.
Note
You cannot edit a default IPS policy, but you can edit a clone of a default IPS policy.
Prerequisites
Log in to the Web UI of the IPS appliance as Operator or Admin.
To modify the match attributes of a custom IPS policy:
Enable the CLI configuration mode.
hostname > enable hostname # configure terminalDisplay the match attributes of the custom IPS policy you want to modify.
In the following example, the custom IPS policy named
myCustom1is a clone of the default IPS policy namedComprehensiveand does not currently specify either of any optional match attributes.hostname (config) # show ips policies myCustom1 Policy attributes : active : no writable : yes modified_date : 2014/09/26 09:51/36 version : 1 Match attributes of policy : attack-target : client attack-target : server min-severity : 1 max-severity : 10 Fingerprint of policy : 2014/09/26 09:51:36 | 791c1c0bcd3b604630616acac14a96b1Change the match attributes of the custom IPS policy.
In the following example, one match attribute (
attack‑target client) is removed from the policy, one match attribute (min‑severity) is overwritten with a new value, and an optional match attribute is added.hostname (config) # no ips policy myCustom1 match attack‑target client hostname (config) # ips policy myCustom1 match min‑severity 3 hostname (config) # ips policy myCustom1 match protocol SNMPVerify your changes, and note that the policy fingerprint is also changed.
hostname (config) # show ips policies myCustom1 Policy attributes : active : no writable : yes modified_date : 2014/09/26 09:51/36 version : 1 Match attributes of policy : protocol : SNMP attack-target : server min-severity : 3 max-severity : 10 Fingerprint of policy : 2014/09/26 11:29:05 | a3c225e74dc2904e2a1109d707f3e963Save your changes.
hostname (config) # write memory
Editing the rule inclusion and exclusion attributes of an IPS policy (CLI)
You can add, change, or remove the rule-exclusion and rule-inclusion attributes of a custom IPS policy only. For a description of all attributes of an IPS policy, see Attributes of IPS policies.
Note
You cannot edit a default IPS policy, but you can edit a clone of a default IPS policy.
Prerequisites
Log in to the Web UI of the IPS appliance as Operator or Admin.
Know the signature ID of the IPS rule that you want to reference. You obtain rule signature IDs from a FireEye customer support representative, or in the drill-down view of an entry in the IPS Events page. For more information, see Details for an IPS event grouping.
To edit the rule-exclusion or rule-inclusion attributes of a custom IPS policy:
Enable the CLI configuration mode.
hostname > enable hostname # configure terminalDisplay the attributes of the custom IPS policy you want to modify.
In the following example, no rule-exclusion or rule-inclusion attributes are defined.
hostname (config) # show ips policies myCustom1 Policy attributes : active : no writable : yes modified_date : 2014/09/26 09:51/36 version : 1 Match attributes of policy : attack-target : client attack-target : server min-severity : 1 max-severity : 10 Fingerprint of policy : 2014/09/26 09:51:36 | 791c1c0bcd3b604630616acac14a96b1Configure rule-exclusion or rule-inclusion attributes of the IPS policy.
The following example adds one rule-exclusion attribute and two rule-inclusion attributes to the custom IPS policy
myCustom3.hostname (config) # ips policy myCustom1 rules exclude 85300001 hostname (config) # ips policy myCustom1 rules include 85300002 hostname (config) # ips policy myCustom1 rules include 85300003Verify your changes.
hostname (config) # show ips policies myCustom1 Policy attributes : active : no writable : yes modified_date : 2014/09/26 11:40:21 version : 4 Match attributes of policy : attack-target : SNMP attack-target : server min-severity : 3 max-severity : 10 Inclusion list for policy : 85300002,85300003 Exception list for policy : 85300001 Fingerprint of policy : 2014/09/26 11:40:21 | 30b14d7ea2ddcae7ccdc6b41ff2c6110Save your changes.
hostname (config) # write memory