In the Web UI, you can use the IPS Configure page to perform the following operations:
Import or export custom IPS rules
Manage IPS policies and monitoring interfaces
Enable or disable the Auto Add Rules feature
Enable or disable detection of IPS reconnaissance or brute-force attacks
Table of policies and interfaces
For each IPS policy defined on the platform, the table displays the following information:
Policy name
Names of the default IPS policies and custom IPS policies you have defined.
Active on interfaces
The monitoring interfaces on which the policy is active.
Rules enabled
Total number of IPS rules selected by the policy.
Actions
Actions you can take on any IPS policy:
Apply—Apply to a monitoring interface.
Clone & edit—Create a custom IPS policy based on a clone of the existing policy.
Remove—Remove policy from the monitoring interfaces.
Actions you can take on custom IPS policies only:
Edit—Edit the attributes of a custom IPS policy and optionally apply it to a monitoring interface
Delete—Delete custom policy.
For information about Web UI page used to edit IPS policies, see IPS policy editor.
Other fields and options
Remove policies from all interfaces
Click to remove all IPS policies from monitoring interfaces. For more information, see Removing all IPS policies from monitoring interfaces (Web UI).
AutoAdd rules
Status of the IPS rules automatic addition feature. This feature applies to active IPS policies only. To show the status (On or Off) of automatic addition of new IPS rules to active interfaces, set the option to the On position. See Managing auto-addition of new IPS rules to active interfaces.
Recon rules
To show the status (On or Off) of IPS detection of reconnaissance activity, set the option to the On position. For more information, see IPS detection of brute-force attacks.