You can enable the IPS-enabled rules engine to perform detailed packet inspection. The rules engine must run in this mode to protect certain protocol ports from brute-force attacks. The list of protocol ports is dynamic, and FireEye controls the list through periodic updates of IPS security content. IPS detailed packet inspection is useful for inspecting traffic flows to email protocols, detecting reconnaissance activity, and detecting brute-force attacks.
Note
IPS detailed packet inspection may slow IPS processing.
Prerequisites
Log in to the IPS appliance as Operator or Admin.
Procedure
Enable the CLI configuration mode.
hostname > enable hostname # configure terminal
Enable detailed packet inspection for brute-force attacks.
hostname (config) # ips detail-filterSave your changes.
hostname (config) # write memory