The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

IPS policy editor

Prev Next

The IPS policy editor enables you to configure the criteria by which an IPS policy selects and applies IPS rules. Typically you begin by creating a clone of a built-in IPS policy and then refine the custom policy. The IPS policy editor enables you to modify a custom IPS policy as follows:

  • Filter the IPS rules displayed.

  • Enable or disable individual IPS rules matched by the policy.

  • Enable or disable forced blocking for an IPS rule matched by the policy.

  • Save your changes and optionally apply the policy to monitoring interfaces.

Policy customization details are described in Editing an IPS policy (Web UI) and Editing an IPS policy (CLI). The remainder of this topic provides an overview of the elements in the IPS policy editor view.

IPS rule summary

The policy editor page displays the following summary information near the top:.

x enabled | y blocked

Displays summary counts of the rules selected by the policy:

  • x—Number of active rules.

  • y—Number of active rules that block malicious traffic (by rule definition or policy override).

Policy configuration table

The table has a row for every IPS rule enabled in the IPS policy.

Enabled

This option is selected if the rule is enabled for the IPS policy you are viewing.

SID

Eight-digit signature ID matched by the rule.

You can filter the list of rules on this field.

Rule Name

Name of an IPS rule in the appliance's IPS rules database.

You can filter the list of rules on this field.

Rule Version

Rule revision number.

Custom Rule

  • yes—The rule is a custom IPS rule.

  • no—The rule is a default IPS rule.

Category

Threat category detected by the rule. For more information about this optional rule-match attribute, see Attributes of IPS policies.

You can filter the list of rules on this field.

Severity

Threat severity level covered by the rule. For more information about this required rule-match attribute, see Attributes of IPS policies.

Direction

Orientation of threats detected by the rule:

  • established

  • not_established

  • from_client

  • to_client

  • from_server

  • to_server

  • no_stream

  • only_stream

You can filter the list of rules on this field.

CVE (Reference ID)

Identification number of the

Common Vulnerabilities and Exposures

(CVE) database entry that describes the vulnerability covered by the rule.

You can filter the list of rules on this field.

Protocol

Network protocol used by the threat detected by the rule. For more information about this optional rule-match attribute, see Attributes of IPS policies.

You can filter the list of rules on this field.

Block

This option is selected if the rule is forced to block matched traffic for the IPS policy you are viewing.