This topic is relevant only if your appliance is deployed inline and the monitoring interface is configured for inline blocking.
When an IPS rule matches a traffic flow, the action taken on the traffic flow is determined by the IPS blocking mode setting on the appliance and the blocking action specified by the matched IPS rule. By default, IPS appliances operate with IPS blocking mode set to enabled. When a traffic flow matches an IPS rule, the system blocks or allows the traffic as specified by the blocking action of the rule. For a detailed description of IPS blocking mode, see Action Overrides to All IPS Rules.
During the initial baselining phase of your IPS deployment, you will likely use the two non-default settings for IPS blocking mode.
Observing IPS in a Production Environment
If you are already running a standard Network Security appliance in a production environment, then initially you might want to evaluate IPS by operating the feature in monitoring mode. If you set IPS blocking mode to disabled), the system generates IPS events, IPS alerts, and IPS notifications, but no traffic is blocked.
Validating IPS Policies and Custom IPS Rules in an Acceptance Testing Environment
To test the accuracy of an IPS policy and custom IPS rules (if you have them), you apply the policy to an interface that carries known test traffic. For this type of testing, all IPS rules must block traffic regardless of the action specified by the matched rules. To configure this behavior, you set IPS blocking mode to all.
After you complete these types of tests, be sure to re‑enable the platform to block or allow matched traffic as specified by the IPS rules. Otherwise, your system will continue to pass all matched traffic or block all matched traffic.
Prerequisites
Log in to the appliance CLI as Admin.
Procedure
After you complete this procedure, the IPS-enabled rules engine no longer blocks or allows traffic as specified by the matched IPS rules. Instead, all matched traffic is blocked (if you set IPS blocking mode to all) or all matched traffic is allowed (if you set IPS blocking mode to disabled).
To disable or force blocking actions for all matched IPS rules:
Enable the CLI configuration mode.
hostname > enable hostname # configure terminalView the current IPS blocking mode. The default value is
enabled.hostname (config) # show ips status IPS enabled : yes IPS feature active : yes IPS feature licensed : yes Auto-update rules for an active policy : enabled IPS blockmode : enabled IPS blockmode last modified: 2014/12/31 16:00:00 IPS configuration status : yes Fully applied to system : yesConfigure the appliance to disable or force IPS blocking, depending on your evaluation needs.
To disable the blocking actions specified by all matched IPS rules:
hostname (config) # ips blockmode disabledTo force blocking action for all matched IPS rules:
hostname (config) # ips blockmode all
Verify your change. In the case of the following example, the system blocks matched traffic for all matched IPS rules, ignoring the blocking actions specified by the rule.
hostname (config) # show ips status IPS enabled : yes IPS feature active : yes IPS feature licensed : yes Auto-update rules for an active policy : disabled IPS blockmode : enabled IPS blockmode last modified: 2015/01/01 00:00:00 IPS configuration status : Fully applied to system : yes(Recommended) Customize appliance login messages to notify users that blocking actions are either disabled or forced for all IPS rules active on the appliance. You can configure three types of login messages:
Local banner—Text that appears after the username is entered in the CLI session.
Remote banner—Text that appears in the Web UI and SSH login pages.
Message of the Day—Text that appears after a user is authenticated and logged in to the CLI.
For more information, see the Network Security System Administration Guide.
Save your changes.
hostname (config) # write memory