The IPS policy editor enables you to configure the criteria by which an IPS policy selects and applies IPS rules. Typically you begin by creating a clone of a built-in IPS policy and then refine the custom policy. The IPS policy editor enables you to modify a custom IPS policy as follows:
Filter the IPS rules displayed.
Enable or disable individual IPS rules matched by the policy.
Enable or disable forced blocking for an IPS rule matched by the policy.
Save your changes and optionally apply the policy to monitoring interfaces.
Policy customization details are described in Editing an IPS policy (Web UI) and Editing an IPS policy (CLI). The remainder of this topic provides an overview of the elements in the IPS policy editor view.
IPS rule summary
The policy editor page displays the following summary information near the top:.
x enabled | y blockedDisplays summary counts of the rules selected by the policy:
x—Number of active rules.
y—Number of active rules that block malicious traffic (by rule definition or policy override).
Policy configuration table
The table has a row for every IPS rule enabled in the IPS policy.
Enabled
This option is selected if the rule is enabled for the IPS policy you are viewing.
SID
Eight-digit signature ID matched by the rule.
You can filter the list of rules on this field.
Rule Name
Name of an IPS rule in the appliance's IPS rules database.
You can filter the list of rules on this field.
Rule Version
Rule revision number.
Custom Rule
yes—The rule is a custom IPS rule.
no—The rule is a default IPS rule.
Category
Threat category detected by the rule. For more information about this optional rule-match attribute, see Attributes of IPS policies.
You can filter the list of rules on this field.
Severity
Threat severity level covered by the rule. For more information about this required rule-match attribute, see Attributes of IPS policies.
Direction
Orientation of threats detected by the rule:
established
not_established
from_client
to_client
from_server
to_server
no_stream
only_stream
You can filter the list of rules on this field.
CVE (Reference ID)
Identification number of the
Common Vulnerabilities and Exposures
(CVE) database entry that describes the vulnerability covered by the rule.
You can filter the list of rules on this field.
Protocol
Network protocol used by the threat detected by the rule. For more information about this optional rule-match attribute, see Attributes of IPS policies.
You can filter the list of rules on this field.
Block
This option is selected if the rule is forced to block matched traffic for the IPS policy you are viewing.