The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Light Weight Policy details

Prev Next

This URL gets the details of a light weight policy associated with a specific interface or sub interface.

Resource URL

GET /sensor/<sensor_id>/interface/<interface_id or subinterface_id>/localipspolicy

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

sensor_id

Sensor Id

Number

Yes

interface_id or subinterface_id

Unique interface or subinterface id

Number

Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

PolicyDescriptor

Baseline IPS policy details

Object

Details of PolicyDescriptor:

Field Name

Description

Data Type

PolicyName

Baseline IPS policy name

String

Description

Policy description

String

IsVisibleToChildren

Is policy visible to child domain

Boolean

InboundRuleSet

Inbound policy rule set

String

OutboundRuleSet

Outbound policy rule set

String

AttackCategory

Attack category

Object

OutboundAttackCategory

Outbound attack category

Object

DosPolicy

DoS policy

Object

ReconPolicy

Recon policy

Object

DosResponseSensitivityLevel

DoS response sensitivity level

Number

IsEditable

Is policy editable

Boolean

Timestamp

Time stamp at which the policy was added

String

VersionNum

Policy version number

Number

IsLightWeightPolicy

Is light weight policy configured

Boolean

Details of object in AttackCategory:

Field Name

Description

Data Type

ExpolitAttackList

List of exploit attacks

Array

Details of object in ExpolitAttackList:

Field Name

Description

Data Type

attackName

Attack name

String

nspId

NSP id of the attack

String

severity

Attack severity, number between 0 & 9

Number

isSeverityCustomized

Is attack severity customized

Boolean

isEnabled

Is attack enabled

Boolean

isAlertCustomized

Is alert customized

Boolean

isRecommendedForSmartBlocking

Is attack recommended for smart blocking

Boolean

AttackResponse

Attack response

Object

notification

Notifications configured

Object

protocolList

List of protocols

Array

applicationsImpactedList

List of applications impacted

Array

attackVector

List of attack vectors

Array

benignTriggerProbability

Attack benign trigger probability

String

target

Attack target, can be "Server" or "Client"

String

blockingType

Blocking type, can be "Attack Packet"

String

subCategory

Attack sub category

String

direction

Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH"

String

isAttackCustomized

Is attack customized

Boolean

Details of object in AttackResponse:

Field Name

Description

Data Type

TCPReset

TCP reset option, can be “DISABLED” / “SOURCE” / “DESTINATION” / “BOTH”

String

isTCPResetCustomized

Is TCP reset customized

Boolean

isICMPSend

Send ICMP host unreachable to source

Boolean

isICMPSendCustomized

Send ICMP host unreachable to source customized

Boolean

mcafeeNACNotification

NAC notification configured, can be “DISABLED” / “ALL_HOSTS” / “MCAFEE_NAC_UNMANAGED_HOSTS”

String

isMcafeeNACNotificationEnabled

Is NAC notification enabled

Boolean

isQuarantineCustomized

Is quarantine customized

Boolean

isRemediateEnabled

Is remediate enabled

Boolean

blockingOption

Blocking option configured, can be “DISABLE” / “ENABLE” / “ENABLE_SMART_BLOCKING”

String

isBlockingOptionCustomized

Is blocking option customized

Boolean

isCapturedPrior

Should application data be captured prior to attack

Boolean

isCapturedPriorCustomized

Should application data be captured prior to attack customized

Boolean

action

Action to be taken on attack, can be “DO_NOTHING” / “SEND_ALERT_AND_LOG_PACKETS” / “SEND_ALERT_ONLY”

String

isLogCustomized

Is logging customized

Boolean

flow

Customixe flow, can be “SINGLE_FLOW” / “FORENSIC_ANALYSIS”

String

isFlowCustomized

Customize flow type

Boolean

isNbytesCustomized

Is logging N bytes in each packet customized

Boolean

numberOfBytesInEachPacket

Number of bytes to be logged in each packet

Object

loggingDuration

Packet logging duration

Object

TimeStamp

Timestamp

String

Details of object in numberOfBytesInEachPacket (Can be either of the below mentioned):

Field Name

Description

Data Type

LogEntirePacket

Log entire packet

Object

CaptureNBytes

Capture N bytes

Object

Details of object in CaptureNBytes:

Field Name

Description

Data Type

NumberOfBytes

Number of bytes to log

Number

Details of object in loggingDuration (Can be either of the below mentioned):

Field Name

Description

Data Type

AttackPacketOnly

Log attack packet only

Object

CaptureNPackets

Capture N packets

Object

CaptureTimeDuration

Capture for a time duration

Object

RestOfFlow

Capture rest of flow

Object

Details of object in CaptureNPackets:

Field Name

Description

Data Type

npackets

Log n packets

number

Details of object in CaptureTimeDuration:

Field Name

Description

Data Type

time

Capture time

String

timeUnit

Time unit, can be "SECONDS" / "MINUTES" / "HOURS" / "DAYS"

String

Details of object in notification:

Field Name

Description

Data Type

isEmail

Is Notification configured through email

Boolean

isPager

Is Notification configured through pager

Boolean

isScript

Is Notification configured through script

Boolean

isAutoAck

Is Notification configured through auto ack

Boolean

isSnmp

Is Notification configured through SNMP

Boolean

isSyslog

Is Notification configured through Syslog

Boolean

isEmailCustomized

Is Notification through email customized

Boolean

isPagerCustomized

Is Notification through pager customized

Boolean

isScriptCustomized

Is Notification through script customized

Boolean

isAutoAckCustomized

Is Notification through auto ack customized

Boolean

isSnmpCustomized

Is Notification through SNMP customized

Boolean

isSyslogCustomized

Is Notification through Syslog customized

Boolean

Details of object in DosPolicy:

Field Name

Description

Data Type

LearningAttack

List of learning attacks

Array

ThresholdAttack

List of threshold attacks

Array

TimeStamp

Time stamp

String

Details of object in LearningAttack:

Field Name

Description

Data Type

attackName

Attack name

String

nspId

NSP id of the attack

String

isSeverityCustomized

Is attack severity customized

Boolean

severity

Attack severity, number between 0 & 9

Number

isBlockingSettingCustomized

Is blocking customized

Boolean

isDropPacket

Drop DoS attack packets of this attack type when detected

Boolean

isAlertCustomized

Is alert customized

Boolean

isSendAlertToManager

Is alert notification to be sent to the Manager configured

String

timeStamp

Time stamp

String

direction

Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH"

String

notification

Notification to be sent via

Object

isAttackCustomized

Is DoS learning attack customized

Boolean

Details of object in ThresholdAttack:

Field Name

Description

Data Type

attackName

Attack name

String

nspId

NSP id of the attack

String

isSeverityCustomized

Is attack severity customized

Boolean

severity

Attack severity, number between 0 & 9

Number

isThresholdValueCustomized

Is threshold value customized

Boolean

isThresholdDurationCustomized

is threshold duration customized

Boolean

ThresholdValue

Threshold values

Number

ThresholdDuration

Threshold Interval (Seconds)

Number

isAlertCustomized

Is alert customized

Boolean

isSendAlertToManager

Is alert notification to be sent to Manager configured

String

TimeStamp

Time stamp

String

Notification

Notification to be sent

Object

direction

Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH"

String

isAttackCustomized

Is DoS threshold attack customized

Boolean

Details of object in ReconPolicy:

Field Name

Description

Data Type

Mandatory

ReconAttackList

List of recon attacks

Array

Yes

TimeStamp

Time stamp

String

Yes

attackName

Attack name

String

yes

nspId

NSP id of the attack

String

Yes

isSeverityCustomized

Is attack severity customized

Boolean

Yes

severity

Severity, number between 0 & 9

Number

Yes

isThresholdValueCustomized

Is threshold value customized

Boolean

Yes

Is Threshold valuecustomized

is threshold duration customized

Boolean

Yes

ThresholdValue

Threshold values

Number

Yes

ThresholdDuration

Threshold Interval (seconds)

Number

Yes

mcAfeeNACNotification

Configured NAC notification that can be

"DISABLED" / "ALL_HOSTS" /

"MCAFEE_NAC_UNMANAGED_HOSTS"

String

Yes

isMcAfeeNACNotificationEnable

Is NAC notification enabled

Boolean

Yes

isQuarantineCustomized

Is quarantine customized

Boolean

Yes

isRemediateEnabled

is remediate enabled

Boolean

Yes

isAlertSuppressionTimerCustom

Is alert suppression customized

Boolean

Yes

alertSuppressionTimer

Alert suppression timer

Number

Yes

IsAlertCustomized

Is alert customized

Boolean

Yes

isSendAlertToManager

Is alert notification to be sent to Manager configured

String

Yes

timestamp

Time stamp

String

Yes

direction

Attack direction that can be "INBOUND" /

"OUTBOUND" / "BOTH"

String

Yes

notification

Notification to be sent via

Object

Yes

isAttackCustomized

Is recon attack customized

Boolean

Yes

Example

Request

GET https://<NSM_IP>/sdkapi/sensor/1001/interface/105/localipspolicy

Response

{
    "PolicyDescriptor":
    {
        "PolicyName": "Local Policy - /My Company/IPS_NS9200/G3/1-G3/2/interface-1",
        "Description": "To test the policies",
        "IsVisibleToChildren": true,
        "InboundRuleSet": "testRuleSet",
        "OutboundRuleSet": "Null",
        "AttackCategory":
       {
           "ExpolitAttackList":
           [
               {
                   "attackName": "IDENT: TinyIdentD Identification Protocol Request Handling Remote Stack Overflow",
                   "nspId": "0x42700e00",
                   "severity": 6,
                   "isSeverityCustomized": true,
                   "isEnabled": true,
                   "isAlertCustomized": false,
                   "isRecommendedForSmartBlocking": false,
                   "AttackResponse":
                   {
                       "TCPReset": "DISABLED",
                       "isTcpResetCustomized": false,
                       "isICMPSend": false,
                       "isICMPSendCustomized": false,
                       "mcAfeeNACNotification": "DISABLED",
                       "isMcAfeeNACNotificationEnabled": false,
                       "isQuarantineCustomized": false,
                       "isRemediateEnabled": false,
                       "blockingOption": "DISABLE",
                       "isBlockingOptionCustomized": false,
                       "isCapturedPrior": true,
                       "isCapturedPriorCustomized": false,
                       "action": "SEND_ALERT_ONLY",
                       "isLogCustomized": false,
                       "isFlowCustomized": false,
                       "isNbytesCustomized": false,
                       "numberOfBytesInEachPacket":
                       {
                           "LogEntirePacket":
                           {
                           }
                       }
                   },
                   "notification":
                   {
                       "isEmail": false,
                       "isPager": false,
                       "isScript": false,
                       "isAutoAck": false,
                       "isSnmp": false,
                       "isSyslog": false,
                       "isEmailCustomized": false,
                       "isPagerCustomized": false,
                       "isScriptCustomized": false,
                       "isAutoAckCustomized": false,
                       "isSnmpCustomized": false,
                       "isSyslogCustomized": false
                   },
                   "protocolList":
                   [
                       "ident"
                   ],
                   "benignTriggerProbability": "3 (Medium)",
                   "blockingType": "attack-packet",
                   "subCategory": "buffer-overflow",
                   "direction": "INBOUND",
                   "isAttackCustomized": true
               }
           ]
       },
       "OutboundAttackCategory":
       {
       },
       "DosPolicy":
       {
           "LearningAttack":
           [
                {
                    "attackName": "Outbound ICMP Echo Request or Reply Volume Too High",
                    "nspId": "0x40018000",
                    "isSeverityCustomized": false,
                    "severity": 7,
                    "isBlockingSettingCustomized": false,
                    "isDropPacket": false,
                    "IsAlertCustomized": false,
                    "isSendAlertToManager": true,
                    "direction": "OUTBOUND",
                    "notification":
                    {
                        "isEmail": false,
                        "isPager": false,
                        "isScript": false,
                        "isAutoAck": false,
                        "isSnmp": false,
                        "isSyslog": false,
                        "isEmailCustomized": false,
                        "isPagerCustomized": false,
                        "isScriptCustomized": false,
                        "isAutoAckCustomized": false,
                        "isSnmpCustomized": false,
                        "isSyslogCustomized": false
                    },
                    "isAttackCustomized": false
                }
            ],
            "ThresholdAttack":
            [
                {
                    "attackName": "Too Many Outbound IP Fragments",
                    "nspId": "0x40018800",
                    "isSeverityCustomized": false,
                    "severity": 6,
                    "isThresholdValueCustomized": false,
                    "isThresholdDurationCustomized": false,
                    "ThresholdValue": 1000,
                    "ThresholdDuration": 5,
                    "isAlertCustomized": false,
                    "isSendAlertToManager": false,
                    "Notification":
                    {
                        "isEmail": false,
                        "isPager": false,
                        "isScript": false,
                        "isAutoAck": false,
                        "isSnmp": false,
                        "isSyslog": false,
                        "isEmailCustomized": false,
                        "isPagerCustomized": false,
                        "isScriptCustomized": false,
                        "isAutoAckCustomized": false,
                        "isSnmpCustomized": false,
                        "isSyslogCustomized": false
                    },
                    "direction": "OUTBOUND",
                    "isAttackCustomized": false
                }
            ],
            "TimeStamp": "2012-08-31 15:20:54.000"
        },
        'ReconPolicy': {
	             'TimeStamp': None,
	             'ReconAttackList': [{
		                    'IsAlertCustomized': False,
		                    'isSeverityCustomized': False,
		                    'direction': None,
		                    'severity': 5,
		                    'isThresholdDurationCustomized': False,
		                    'isSendAlertToManager': False,
		                    'isQuarantineCustomized': False,
		                    'attackName': 'BOTHeuristic: PotentialBotActivity-
MultipleResetsfromSMTPreceiver',
		                    'ThresholdDuration': 0,
		                    'alertSuppressionTimer': 0,
		                    'isAlertSuppressionTimerCustomized': False,
		                    'isAttackCustomized': False,
		                    'isMcAfeeNACNotificationEnabled': False,
		                    'isThresholdValueCustomized': False,
		                    'nspId': '0x43f00900',
		                    'mcAfeeNACNotification': 'DISABLED',
		                    'isRemediateEnabled': False,
		                    'timeStamp': None,
		                    'ThresholdValue': 0,
		                    'notification': {
			                          'isSnmp': False,
			                          'isAutoAckCustomized': False,
			                          'isPagerCustomized': False,
			                          'isSyslogCustomized': False,
			                          'isEmail': False,
			                          'isSyslog': False,
			                          'isScriptCustomized': False,
			                          'isSnmpCustomized': False,
			                          'isScript': False,
			                          'isPager': False,
			                          'isEmailCustomized': False,
			                          'isAutoAck': False
		                    }
	             }]
        },
        "DosResponseSensitivityLevel": 0,
        "IsEditable": false,
								"Timestamp": "2012-08-31 15:20:55.000",
								"VersionNum": 1, 
								"IsLightWeightPolicy": true
    }
}
       

Error Information

Following error codes are returned by this URL:

S.No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

404

1106

Invalid Sensor

2

404

1107

Invalid interface or sub-interface id

3

400

1301

The number of attacks does not match the number in the baseline policy

4

400

1302

Number of bytes has to be between 1 to 255

5

400

1303

Please provide the number of bytes to be logged

6

400

1304

Please provide duration of logging for flow

7

400

1305

Number of bytes has to be between 2 to 255

8

400

1306

Time has to be between 1 to 63

9

400

1307

Please provide a time

10

400

1308

Please provide a time interval

11

400

1309

Please provide the flow

12

400

1310

Invalid severity - please provide a value between 0 and 10

13

400

1311

Invalid threshold value - please enter a value between 1 and 2147483647

14

400

1312

Invalid threshold duration - please enter a value between 1 and 2147483647

15

400

1311

Alert suppression timer should be between 1 and 65535