The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling detailed inspection mode (CLI)

Prev Next

You can enable the IPS-enabled rules engine to perform detailed packet inspection. The rules engine must run in this mode to protect certain protocol ports from brute-force attacks. The list of protocol ports is dynamic, and FireEye controls the list through periodic updates of IPS security content. IPS detailed packet inspection is useful for inspecting traffic flows to email protocols, detecting reconnaissance activity, and detecting brute-force attacks.

Note

IPS detailed packet inspection may slow IPS processing.

Prerequisites
  • Log in to the IPS appliance as Operator or Admin.

Procedure
To enable detailed packet inspection for brute-force attacks:
  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Enable detailed packet inspection for brute-force attacks.

    hostname (config) # ips detail-filter
  3. Save your changes.

    hostname (config) # write memory