The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Manage IPS policies

Prev Next

The Manager provides an ultimate refining tool for IPS policy management, by bringing together ignore rules and attack set profiles for final customization before deployment. Using IPS policies, you can select the exact Exploit and Denial of Service (DoS) attacks you want to protect against, the types of automatic responses you need to block current or further impacts, and the methods of notification that will help your team respond to malicious use of your network in the most expeditious time.

The IPS page provides the following actions:

  • Launch the Custom Attack Editor. See Custom Attack Definitions section.

    For more information on types of custom attacks, see Types of custom attacks.

  • Adding an IPS policy

  • Copying an IPS policy: Copying duplicates an existing policy, and is similar to a "save as" function. You can edit a Trellix IPS-provided policy. However, if you want to copy a policy, you can copy an existing policy to further refine the policy for application in a new environment. You can copy a predefined policy, save it under a new name, and customize it for your unique environment.

    Copying a provided policy specifically enables you to add or subtract from the default settings of a policy. For example, you might find a signature is generating false positives, and you might want to disable the alerting of the signature's attack. Also, you might receive attacks uncommon to a network environment that are affecting your system and you want to add specific attacks to a policy for added security.

  • Viewing/editing an IPS policy: Editing an IPS policy allows you to make the changes necessary to match the policy with the traffic you are monitoring. Editing a policy permanently changes that policy. However, every time you edit a policy, a new version is created. This enables you to revert the changes by going back to an older version. To make modifications or updates to a policy, try the following:

    • If you intend to make slight changes to a policy but want to save it under a different name, try cloning an IPS policy.

    • If you edit a predefined policy and later want to recreate that policy as it was when provided by Trellix, simply revert to the earlier version of the policy. If you had deleted the earlier versions, add a policy and apply the inbound and outbound attack set profile that matches the original policy you want to recreate.

    Note

    In the IPS page, the Last Updated column displays the time stamp of when a policy was last modified. The Last Updated-By column displays the logon name of the user who modified it. For policies defined in the Central Manager, the Last Updated-By column shows NSCM Defined Policy as the value.

  • Deleting an IPS policy.