This topic covers the following information:
Report Overview
The IPS Policy Configuration Details report provides a high-level view of active IPS policies, followed by a list of IPS rules activated by the policies.
You can request the report to be output as a PDF file or as a CSV file in the /data/reports folder on the local drive. The format of the report file name is ips_policy_configuration_detail_hostName_dateCreated_timeCreated, where hostName is the host name assigned to your appliance, and dateCreated and timeCreated identify the date and time the report was created.
The report contains the following sections for each active monitoring interface:
Identification of active IPS policies by monitoring interface
At the top of the report, two colored boxes identify the active IPS policies by monitoring interface.
In the following example, the platform has one monitoring interface and the default IPS policy Comprehensive is active on the interface:

In the following example, the platform has two monitoring interfaces and the custom IPS policies a_policy and b_policy are active on the interfaces:

Count of active and excluded rules per active monitoring interface
The first interface-specific section of the report displays two colored boxes:
Active Rules—The number of active IPS rules for the active monitoring interface.
Rules Excluded—The number of IPS rules explicitly excluded by an attribute of the IPS policy applied to the monitoring interface. Note: You can configure rule-exclusion and rule-inclusion attributes for custom IPS policies only.
In the following example, the IPS policy applied to the monitoring interface matches 1199 IPS rules in the appliance database. If the IPS policy is configured with IPS rule exclusion attributes, none of those attributes affect the matched IPS rules, because the number of Rules Excluded is 0.

Summary of active rules per active monitoring interface
For each active interface, the second section breaks down the active rules (but not the excluded rules) into the following statistics:
Protocol
Number of IPS rules that cover vulnerabilities in each protocol, such as HTTP, NetBIOS, POP3, DNS, DHCP, and Telnet.
Note
Default xIPS policies do not use the name of the exploited protocol as a rule-selection criterion.
Attack target
Number of IPS rules that cover vulnerabilities related to each target host type, such as client, server, or client or server.
Threat category
Number of IPS rules that cover vulnerabilities within each supported threat category, such as denial_of_service, exploit, or other.
Note
Default IPS policies do not use the name of the exploited protocol as a rule-selection criteria.
Number of IPS rules by threat severity level
Number of IPS rules that cover vulnerabilities within each supported threat severity range: Critical (7 ‑ 10), Major (4 ‑ 6), or Minor (1 ‑ 3).
IPS policy match attributes
Lists each match attribute specified in the IPS policy.
Note
Default IPS policies do not use the name of the exploited protocol or the threat category as a rule-selection criterion.
For more information, see the Rule match attributes section in Attributes of IPS policies.
In the following example, a custom IPS policy specifies match criteria for the exploit threat category, for the HTTP protocol, for both the client and server as attack targets, and minimum and maximum severity levels 1 and 10.

List of active rules per monitoring interface
For each active interface, the third section lists all active rules, including the following information:
Rule name
Threat severity category (minor, major, or critical)
Attack target
CVE ID (if the IPS rule references a vulnerability in the CVE database)
Attack category
Protocol
Does it block? (Yes or No)
Report prerequisites
Log in to the Web UI of the IPS appliance as Monitor, Analyst, Operator, or Admin.
Generating an IPS policy configuration details report (Web UI)
To generate an IPS policy configuration details report:
In the Web UI, choose Reports > Reports.
In the Report Type field, select IPS Policy Configuration Details,
In the Report Format field, select the report output format.
pdf—Write the report to an Adobe PDF file.
csv—Write the report to a CSV file.
Click Generate Report. The page confirms receipt of your request.
When the report is complete, a link to the report file displays below the Generate Reports label.
Scheduling an IPS policy configuration details report (Web UI)
To schedule an IPS policy configuration details report:
In the Web UI, choose Reports > Schedule.
In the Scheduled field, select the report frequency:
hourly
daily
weekly
monthly
In the Time fields, specify the report time.
If you selected a weekly report, specify the report day of the week in the WeekDay field.
If you selected a monthly report, specify the report day of the month in the MonthDay field.
In the Delivery field, select the report delivery method:
email—Deliver the report as a file attached to email. For information about configuring email notification, see the Network Security User Guide.
file—Deliver the report as a file linked from the Web UI.
In the Report Type field, select IPS Policy Configuration Details.
In the Report Format field, select the report output format.
pdf—Write the report to an Adobe PDF file.
csv—Write the report to a CSV file.
Click Schedule Report. The page confirms receipt of your request.
When the report is complete, a link to the report file displays below the Generate Reports label.