Be aware of the usage guidelines and caveats described in the following paragraphs.
General Usage Guidelines
$HOME_NET—A set of alert policy exceptions can support more granular applications of alert action overrides than the homenet address or mask for Snort custom rules. See Custom rules and the
homenetcommand in the CLI Command Reference.Usage statistics—Use CLI commands to see the number of alert policy exceptions applied. See Viewing the list of alert policy exceptions using the CLI .
Logically ANDed terms—The match terms of an alert policy exception are matched using implicit AND operators. Logical OR operators are not available.
Attack direction-agnostic addresses—Alert policy exceptions do not refer "victim" and "attacker" IP addresses. Alert policy exceptions are defined using "source" and "destination" addresses as present in the packet, and attack direction is not considered.
Matching order—In cases where alert policy exceptions overlap or conflict, the following matching order determines which exception is applied:
signature ID
>signature name>attack category>all signaturesLongest prefix match—For matching source or destination addresses, the one with the longest prefix is most specific. For example, the following ruleset blocks traffic for the same signature when seen from a specific subnet. Rule 2 is more specific than Rule 1.
Rule 1: SigID=900000 SrcIP=10.1.0.0/16 DstIP=ANY Intf=ALL Action=Block
Rule 2: SigID=900000 SrcIP=10.1.1.1/32 DstIP=ANY Intf=ALL Action=Suppress
Supported alerts—Alert policy exceptions support the following attack categories:
Infection Match
Domain Match
Malware Callback
Riskware
IPS
Reconnaissance
Local Signature
Supported addresses—Alert policy exceptions support both IPv4 and IPv6 addresses.
General limitations
Alerts not supported—Alerts for the following attack categories are not supported:
Malware Objects
Web Infections
SmartVision
SmartVision rules can be whitelisted separately. See "Managing Noisy SmartVision Alerts" in the Network Security SmartVision Feature Guide.
Maximum rules—Up to 2500 alert policy exceptions are supported per appliance.
Caveats for blocking actions
The following paragraphs describe how alert policy exceptions interact with inline blocking.
Override Actions That Entail Blocking Are Supported on Inline Blocking Deployments Only
Alert policy exceptions support the following override actions only for interfaces configured for inline blocking mode on appliances deployed inline:
Block—Forced blocking of matched traffic.
UnBlock—Allowing matched traffic.
Suppress & Unblock—Suppression of alert notifications and event logging while at the same time allowing matched traffic.
The alert policy exception Suppress and Default override actions are not dependent on inline blocking mode and inline deployment.
Multiple signature rules are more precise than a signature ame
For an alert policy exception that applies an UnBlock override action, Trellix recommends that you specify a signature ID rather than a signature name. Otherwise, the alert policy exception may allow more traffic to pass than you intend.
Caveats for IPS Rules
The following paragraphs describe how alert policy exceptions interact with IPS rules.
Only Suppression Is Supported for Reconnaissance Activity and Brute-Force Attack Rules
When an alert policy exception matches traffic for an IPS rule that detects reconnaissance activity or brute-force attacks, only suppression is supported as an override activity.
IPS Blocking Mode "Disabled" and "All" Take Precedence Over Alert Policy Exceptions
When the appliance is deployed inline and for interfaces configured for inline blocking mode, IPS blocking mode can be used to deny or force blocking of traffic matched by IPS rules. IPS blocking mode is enabled by default. The other two IPS blocking modes take precedence over alert policy exceptions:
When IPS blocking mode is disabled, all matched IPS rules—including those with alert policy exceptions that specify forced blocking—act as detection-only rules.
When IPS blocking mode is all, all matched IPS rules—including those with alert policy exceptions that specify "UnBlock"—act as blocking rules. In addition, IPS alert notifications are generated and IPS events are logged.
For more information, see "Action Overrides to All IPS Rules" in the Network Security IPS Feature Guide and the ips blockmode command in the CLI Command Reference.