The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Editing an IPS policy (CLI)

Prev Next

Using the CLI, you can edit the rule match, rule inclusion, and rule exclusion attributes of a policy:

  • Editing the rule match attributes of an IPS policy (CLI)

  • Editing the rule inclusion and exclusion attributes of an IPS policy (CLI)

To override the actions specified by rules selected by an IPS policy, you must use the Web UI.

Note

You cannot edit a default IPS policy, but you can edit a clone of a default IPS policy. See Cloning an IPS policy (CLI).

Editing the rule match attributes of an IPS policy (CLI)

You can add, change, or remove the match attributes of a custom IPS policy only. For a description of all attributes of an IPS policy, see Attributes of IPS policies.

Note

You cannot edit a default IPS policy, but you can edit a clone of a default IPS policy.

Prerequisites
  • Log in to the Web UI of the IPS appliance as Operator or Admin.

To modify the match attributes of a custom IPS policy:

  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Display the match attributes of the custom IPS policy you want to modify.

    In the following example, the custom IPS policy named myCustom1 is a clone of the default IPS policy named Comprehensive and does not currently specify either of any optional match attributes.

    hostname (config) # show ips policies myCustom1
    Policy attributes : 
    	active : no
    	writable : yes
    	modified_date : 2014/09/26 09:51/36
    	version : 1
     
    Match attributes of policy : 
    	attack-target : client
    	attack-target : server
    	min-severity : 1
    	max-severity : 10
     
    Fingerprint of policy :
    2014/09/26 09:51:36 | 791c1c0bcd3b604630616acac14a96b1
  3. Change the match attributes of the custom IPS policy.

    In the following example, one match attribute (attack‑target client) is removed from the policy, one match attribute (min‑severity) is overwritten with a new value, and an optional match attribute is added.

    hostname (config) # no ips policy myCustom1 match attack‑target client
    hostname (config) # ips policy myCustom1 match min‑severity 3
    hostname (config) # ips policy myCustom1 match protocol SNMP
  4. Verify your changes, and note that the policy fingerprint is also changed.

    hostname (config) # show ips policies myCustom1
    Policy attributes : 
    		active : no
    		writable : yes
    		modified_date : 2014/09/26 09:51/36
    		version : 1
     
    Match attributes of policy : 
    		protocol : SNMP
    		attack-target : server
    		min-severity : 3
    		max-severity : 10
     
    Fingerprint of policy :
    2014/09/26 11:29:05 | a3c225e74dc2904e2a1109d707f3e963
  5. Save your changes.

    hostname (config) # write memory
Editing the rule inclusion and exclusion attributes of an IPS policy (CLI)

You can add, change, or remove the rule-exclusion and rule-inclusion attributes of a custom IPS policy only. For a description of all attributes of an IPS policy, see Attributes of IPS policies.

Note

You cannot edit a default IPS policy, but you can edit a clone of a default IPS policy.

Prerequisites
  • Log in to the Web UI of the IPS appliance as Operator or Admin.

  • Know the signature ID of the IPS rule that you want to reference. You obtain rule signature IDs from a FireEye customer support representative, or in the drill-down view of an entry in the IPS Events page. For more information, see Details for an IPS event grouping.

To edit the rule-exclusion or rule-inclusion attributes of a custom IPS policy:

  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Display the attributes of the custom IPS policy you want to modify.

    In the following example, no rule-exclusion or rule-inclusion attributes are defined.

    hostname (config) # show ips policies myCustom1
    Policy attributes : 
            active : no
            writable : yes
            modified_date : 2014/09/26 09:51/36
            version : 1
     
    Match attributes of policy : 
    		attack-target : client
    		attack-target : server
    		min-severity : 1
    		max-severity : 10
     
    Fingerprint of policy :
    2014/09/26 09:51:36 | 791c1c0bcd3b604630616acac14a96b1
  3. Configure rule-exclusion or rule-inclusion attributes of the IPS policy.

    The following example adds one rule-exclusion attribute and two rule-inclusion attributes to the custom IPS policy myCustom3.

    hostname (config) # ips policy myCustom1 rules exclude 85300001
    hostname (config) # ips policy myCustom1 rules include 85300002
    hostname (config) # ips policy myCustom1 rules include 85300003
  4. Verify your changes.

    hostname (config) # show ips policies myCustom1
    Policy attributes : 
            active : no
            writable : yes
            modified_date : 2014/09/26 11:40:21
            version : 4
     
    Match attributes of policy : 
            attack-target : SNMP
            attack-target : server
            min-severity : 3
            max-severity : 10
     
    Inclusion list for policy :
            85300002,85300003
     
    Exception list for policy :
            85300001
     
    Fingerprint of policy :
    2014/09/26 11:40:21 | 30b14d7ea2ddcae7ccdc6b41ff2c6110
  5. Save your changes.

    hostname (config) # write memory