The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Interface IPS

Prev Next

An attack can be added to a specific interface which updates the existing policy of that interface. This depends on the interface from where the alert was generated. When an attack is added to the policy, the policy for that interface is updated. The attack is added to the selected policy set of that interface.

Note

This option is not visible for NTBA appliances.

To add the attack to the policy:

Steps:

  1. Navigate to Analysis → <Admin Domain Name> → Attack Log.

  2. Select the alert, click Other Actions at the bottom of the page.

  3. Select Update Policy, and click (Interface IPS) /<Admin Domain Name>/<Device Name>/<Interface>.

    The <Attack Name> panel opens.

  4. Make the required changes to the policy settings and click Update.

    The attack is added to the selected policy set of that interface only.

    To view/edit the attack added to the policy of that interface:

    1. Navigate to Policy → <Admin Domain Name> → Intrusion Prevention → Policy Manager.

    2. Double-click the interface for which the policy is updated.

      The <Device Name>/<Interface> panels opens on the right side. You can view the attack added under Customized Attacks in the IPS section.