The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Optional: Disabling or forcing blocking for all IPS rules (CLI)

Prev Next

This topic is relevant only if your appliance is deployed inline and the monitoring interface is configured for inline blocking.

When an IPS rule matches a traffic flow, the action taken on the traffic flow is determined by the IPS blocking mode setting on the appliance and the blocking action specified by the matched IPS rule. By default, IPS appliances operate with IPS blocking mode set to enabled. When a traffic flow matches an IPS rule, the system blocks or allows the traffic as specified by the blocking action of the rule. For a detailed description of IPS blocking mode, see Action Overrides to All IPS Rules.

During the initial baselining phase of your IPS deployment, you will likely use the two non-default settings for IPS blocking mode.

Observing IPS in a Production Environment

If you are already running a standard Network Security appliance in a production environment, then initially you might want to evaluate IPS by operating the feature in monitoring mode. If you set IPS blocking mode to disabled), the system generates IPS events, IPS alerts, and IPS notifications, but no traffic is blocked.

Validating IPS Policies and Custom IPS Rules in an Acceptance Testing Environment

To test the accuracy of an IPS policy and custom IPS rules (if you have them), you apply the policy to an interface that carries known test traffic. For this type of testing, all IPS rules must block traffic regardless of the action specified by the matched rules. To configure this behavior, you set IPS blocking mode to all.

After you complete these types of tests, be sure to re‑enable the platform to block or allow matched traffic as specified by the IPS rules. Otherwise, your system will continue to pass all matched traffic or block all matched traffic.

Prerequisites
  • Log in to the appliance CLI as Admin.

Procedure

After you complete this procedure, the IPS-enabled rules engine no longer blocks or allows traffic as specified by the matched IPS rules. Instead, all matched traffic is blocked (if you set IPS blocking mode to all) or all matched traffic is allowed (if you set IPS blocking mode to disabled).

To disable or force blocking actions for all matched IPS rules:

  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. View the current IPS blocking mode. The default value is enabled.

    hostname (config) # show ips status
    
    IPS enabled          : yes
    IPS feature active   : yes
    IPS feature licensed : yes
    Auto-update rules for an active policy : enabled
    IPS blockmode : enabled
    IPS blockmode last modified: 2014/12/31 16:00:00
    
    IPS configuration status : yes
    	Fully applied to system : yes
  3. Configure the appliance to disable or force IPS blocking, depending on your evaluation needs.

    • To disable the blocking actions specified by all matched IPS rules:

      hostname (config) # ips blockmode disabled
    • To force blocking action for all matched IPS rules:

      hostname (config) # ips blockmode all
  4. Verify your change. In the case of the following example, the system blocks matched traffic for all matched IPS rules, ignoring the blocking actions specified by the rule.

    hostname (config) # show ips status
    
    IPS enabled          : yes
    IPS feature active   : yes
    IPS feature licensed : yes
    
    Auto-update rules for an active policy : disabled
    
    IPS blockmode : enabled
    IPS blockmode last modified: 2015/01/01 00:00:00
    
    
    IPS configuration status :
    Fully applied to system : yes
  5. (Recommended) Customize appliance login messages to notify users that blocking actions are either disabled or forced for all IPS rules active on the appliance. You can configure three types of login messages:

    • Local banner—Text that appears after the username is entered in the CLI session.

    • Remote banner—Text that appears in the Web UI and SSH login pages.

    • Message of the Day—Text that appears after a user is authenticated and logged in to the CLI.

    For more information, see the Network Security System Administration Guide.

  6. Save your changes.

    hostname (config) # write memory