Administrators often disable the blocking actions specified by matched IPS rules while they are evaluating the fit of IPS rules to the network traffic. While IPS blocking mode is disabled, the IPS platform operates with standard malware rules in blocking mode (as specified in the malware rule definitions) but with IPS rules in detection-only mode. Matched IPS rules do not affect monitored traffic flows, but the matched traffic generates IPS events, IPS alerts, and IPS event notifications. For more information, see Action overrides to all IPS rules.
Important
If you disabled IPS blocking mode while evaluating the fit of IPS rules to your environment, be sure to follow these steps to re‑enable IPS blocking mode after you finish configuring IPS.
Prerequisites
Log in to the appliance CLI as Admin.
Procedure
After you complete this procedure, the IPS-enabled rules engine blocks or allows traffic as specified by the matched IPS rules.
To re-enable blocking actions as specified by matched IPS rules:
Enable the CLI configuration mode.
hostname > enable hostname # configure terminalClear IPS blocking mode.
hostname (config) # no ips blockmodeVerify your change.
hostname (config) # show ips status License status : enabled Auto-update rules for an active policy : enabled IPS blockmode : enabled IPS blockmode last modified: 2015/01/01 00:00:00 IPS configuration status : Fully applied to system : yes(Recommended) Customize appliance login messages to notify users that blocking actions are enabled for all IPS rules active on the appliance. You can configure three types of login messages:
Local banner—Text that appears after the username is entered in the CLI session.
Remote banner—Text that appears in the Web UI and SSH login pages.
Message of the Day—Text that appears after a user is authenticated and logged in to the CLI.
For more information, see the Network Security System Administration Guide.
Save your changes.
hostname (config) # write memory