The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Removing a single IPS policy from monitoring or management interfaces (CLI)

Prev Next

To stop applying IPS rules to a monitoring or a management interface, remove the active IPS policy from the interface. Without an IPS policy applied, traffic that passes through the interface is analyzed using standard Network Security content rules only. When using standard Network Security content rules alone, the platform detects and, if deployed and configured inline, can block client-centric HTTP-based malware only.

To delete a custom IPS policy definition from an IPS platform, see Deleting a custom IPS policy (CLI).

Prerequisites
  • Log in to the CLI of the IPS platform as Operator or Admin.

Procedure

To stop applying policy-selected IPS rules to the traffic at an interface:

  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Display the appliance interfaces and the current application of IPS policies to interfaces.

    In the following example, the appliance has two interfaces and two default IPS policies are active on the interfaces.

    hostname (config) # show ips interfaces active
    	A : FireEye_Default
    	B : myCustom1
  3. To remove an IPS policy from an interface, enter the CLI command no ips apply <policyName> interface <interfaceName>, where <interfaceName> specifies the interface from which the policy is to be removed.

    In the following example, the custom IPS policy named myCustom1 is removed from interface B.

    hostname (config) # no ips apply myCustom1 interface B
  4. Verify the updated application of IPS policies to interfaces.

    In the following example, the custom IPS policy named myCustom1 is removed from interface B.

    hostname (config) # show ips interfaces active
    	A : FireEye_Default
    	B : empty

    Traffic that passes through interface B is analyzed using standard Network Security content rules only.

  5. Save your changes.

    hostname (config) # write memory