The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Managing auto-addition of new IPS rules to active interfaces

Prev Next

You can use either the Web UI or the CLI to manage automatic addition of new IPS rules to active monitoring and management interfaces:

  • About auto‑addition of new IPS rules to active interfaces

  • Enabling or disabling auto-addition of new IPS rules to active interfaces (Web UI)

  • Enabling or disabling auto-addition of new IPS rules to active interfaces (CLI)

About auto‑addition of new IPS rules to active interfaces

When IPS policies are active, the IPS-enabled rules engine uses the policy-selected IPS content rules to analyze traffic. The Auto Add Rules option determines whether the rules engine re-evaluates active policies when the database of IPS rules is updated.

  • The Auto Add Rules option is enabled by default. If your platform receives new IPS security content rules, the system re-evaluates active IPS policies against the updated database of IPS rules.

  • If your platform receives new IPS security content rules while Auto Add Rules is disabled, the system does not re‑evaluate active IPS policies against the updated database of IPS rules. In this case, you can force the platform to re‑evaluate an active policy. By removing the policy from an interface and then reapplying the policy to the interface.

  • You enable or disable the Auto Add Rules option globally (for all monitoring and management interfaces on the platform). You cannot apply the option on a per-port, per-interface, or per-policy basis.

An IPS platform's rules database can receive new IPS rules from two different sources:

  • A scheduled or explicit update of security content includes new FireEye-provided IPS rules

  • You explicitly import or delete custom IPS rules

Note

The Auto Add Rules option applies to Trellix-provided IPS rules that are obtained through security content downloads. The option does not apply to custom IPS rules.

Enabling or disabling auto-addition of new IPS rules to active interfaces (Web UI)

This topic describes how to disable or re-enable automatic addition of new IPS rules to active interfaces using the Web UI.

The Auto Add Rules option is enabled by default. When security content updates load new IPS rules, the appliance automatically re‑evaluates active IPS policies and—if any new rules match the policy match attributes—the new rules are included at the associated interface.

If the Auto Add Rules option is disabled when security content updates load new IPS rules, the appliance does not automatically re-evaluate active IPS policies. You can force the platform to re-evaluate active policies by removing the policies from monitoring interfaces and then re-applying the policies to the interfaces.

Note

The Auto Add Rules option applies to IPS rules provided by Trellix through security content downloads. The option does not apply to custom IPS rules.

For more information, see Managing auto-addition of new IPS rules to active interfaces.

Prerequisites
  • Log in to the Web UI of the IPS platform as Operator or Admin.

Procedure

To disable or re-enable automatic addition of new standard IPS rules to active IPS policies:

  1. Choose IPS > Configure.

  2. Go to the IPS policy for which you want to disable or re-enable automatic addition of new standard IPS rules while the policy is active.

  3. Clear or set the AutoAdd Rules option.

Enabling or disabling auto-addition of new IPS rules to active interfaces (CLI)

This topic describes how to disable or re-enable automatic addition of new IPS rules to active interfaces using the CLI. The Auto Add Rules option is enabled by default. If your platform receives new IPS security content rules, the system re-evaluates active IPS policies against the updated database of IPS rules.

Note

The Auto Add Rules option applies to Trellix-provided IPS rules that are obtained through security content downloads. The option does not apply to custom IPS rules.

For more information, see Managing auto-addition of new IPS rules to active interfaces.

Prerequisites
  • Log in to the CLI of the IPS platform as Operator or Admin.

Procedure

To disable or re-enable automatic addition of new standard IPS rules to active IPS policies:

  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Display the status of the automatic IPS rule addition feature for active IPS policies. In the following example, the Auto‑update rules for an active policy field shows that the Auto Add Rules option is enabled.

    hostname (config) # show ips status
     
    IPS enabled          : yes
    IPS feature active   : yes
    IPS feature licensed : yes
     
    Auto-update rules for an active policy : enabled
     
    IPS blockmode : disabled
    IPS blockmode last modified: 2018/10/20 20:59:14
     
    IPS configuration status :
    	 Fully applied to system : yes
  3. (Optional) Toggle the setting of the feature.

    • If the feature is enabled, you can disable the feature.

      hostname (config) # no ips auto-update enable
    • If the feature is disabled, you can re‑enable the feature.

      hostname (config) # ips auto-update enable
  4. Verify the configuration change. In the following example, the Auto-update rules for an active policy field shows that the Auto Add Rules option is disabled.

    hostname (config) # show ips status
    
    IPS enabled          : yes
    IPS feature active   : yes
    IPS feature licensed : yes
    Auto-update rules for an active policy : disabled
     
    IPS blockmode : disabled
    IPS blockmode last modified: 2018/10/20 20:59:14
     
    IPS configuration status :
            Fully applied to system : yes
  5. Save your changes.

    hostname (config) # write memory