The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling IPS detection of reconnaissance activity (CLI)

Prev Next

IPS detection of reconnaissance activity is disabled by default. If you enable this feature, the platform triggers IPS events when reconnaissance activity is detected.

Note

Reconnaissance detection consumes additional system resources. Depending on your traffic load and IPS policies, operating the platform in reconnaissance detection mode can slow IPS processing.

The platform uses default threshold values for ping sweep detection and port scan detection. You can configure higher detection thresholds to reduce false positive IPS events. See Configuring the detection thresholds for reconnaissance events (CLI).

Prerequisites
  • Log in to the CLI of the IPS appliance as Operator or Admin.

Procedure
To enable or disable IPS detection of reconnaissance activity:
  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Check the current status of the feature. In the following example, the feature is not yet enabled.

    hostname (config) # show ips reconnaissance
    IPS reconnaissance is disabled
  3. Enable or disable the feature. In the following example, the command enables the feature.

    hostname (config) # ips reconnaissance enable
  4. Confirm your changes. The following example displays the default settings.

    hostname (config) # show ips reconnaissance
    Ping sweep threshold  : 20
    Port scan threshold   : 200
    Brute force threshold : 5
  5. Save your changes.

    hostname (config) # write memory