The Trellix Intrusion Prevention System IPS offers a variety of ways to block malicious traffic. These options include the following:
Block exploit traffic (based on IPS policy configuration)
Block DoS traffic (behavior-based detection)
Block malware download (based on Malware policies)
Block using Firewall policies (based on ACLs in the Firewall policies)
Use Trellix IPS's traffic normalization feature—block based on configured TCP flow violation (out-of-order packets, deny…)
Block IP-spoofed packets (configured)
Tip
Ignore rules can be configured to override the blocking criteria—to permit particular source IPs, for example.
The Malware, Firewall, and DoS are detailed in their respective chapters of this Guide.