After you specify the security policies to be applied, the Sensor scans the traffic according to these policies and takes the configured action when it finds a matching traffic flow. However, there could be instances where you do not want certain traffic to be treated as an attack by the Sensor even though this traffic might match a specific attack definition. Consider some of this traffic might appear as an attack. You are aware of the purpose of this traffic and you do not want the Sensor to take any response action on this traffic. However, if similar traffic is generated by any other server, you want the Sensor to treat it as an attack and respond accordingly. Trellix IPS provides various options to handle such situations, which are discussed in this chapter.
How to create Ignore rules for an applied IPS policy
- Published on Oct 5, 2026
- 1 minute(s) read
Was this article helpful?