To stop applying IPS rules to a monitoring or a management interface, remove the active IPS policy from the interface. Without an IPS policy applied, traffic that passes through the interface is analyzed using standard Network Security content rules only. When using standard Network Security content rules alone, the platform detects and, if deployed and configured inline, can block client-centric HTTP-based malware only.
To delete a custom IPS policy definition from an IPS platform, see Deleting a custom IPS policy (CLI).
Prerequisites
Log in to the CLI of the IPS platform as Operator or Admin.
Procedure
To stop applying policy-selected IPS rules to the traffic at an interface:
Enable the CLI configuration mode.
hostname > enable hostname # configure terminalDisplay the appliance interfaces and the current application of IPS policies to interfaces.
In the following example, the appliance has two interfaces and two default IPS policies are active on the interfaces.
hostname (config) # show ips interfaces active A : FireEye_Default B : myCustom1To remove an IPS policy from an interface, enter the CLI command
no ips apply <policyName> interface <interfaceName>, where<interfaceName>specifies the interface from which the policy is to be removed.In the following example, the custom IPS policy named
myCustom1is removed from interface B.hostname (config) # no ips apply myCustom1 interface BVerify the updated application of IPS policies to interfaces.
In the following example, the custom IPS policy named
myCustom1is removed from interface B.hostname (config) # show ips interfaces active A : FireEye_Default B : emptyTraffic that passes through interface B is analyzed using standard Network Security content rules only.
Save your changes.
hostname (config) # write memory