The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Removing all IPS policies from all interfaces (CLI)

Prev Next

You can remove IPS policies from all interfaces in a single step instead of removing policies individually from each interface. Without IPS policies applied to monitoring interfaces, the platform functions as a standard Network Security appliance that detects and, if deployed and configured inline, can block client-centric HTTP-based malware.

To delete a custom IPS policy definition from an IPS platform, see Deleting a custom IPS policy (CLI).

Prerequisites
  • Log in to the CLI of the IPS platform as Operator or Admin.

Procedure

To stop applying policy-selected IPS rules to the traffic at all interfaces:

  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Display the appliance interfaces and the current application of IPS policies to appliance interfaces.

    In the following example, the appliance has two interfaces and two default IPS policies are active on the interfaces.

    hostname (config) # show ips interfaces
    Interface : A
    	Policy applied : FireEye_Default
    	Rule count : 2640
    Interface : B
    	Policy applied : Comprehensive
    	Rule count : 6882
  3. Remove all IPS policies from all interfaces.

    hostname (config) # no ips apply all
  4. Confirm your configuration changes.

    hostname (config) # show ips interfaces
    Interface : A
    	Policy applied : empty
    	Rule count : 0
    Interface : B
    	Policy applied : empty
    	Rule count : 0

    Without IPS policies applied to interfaces, the platform functions as a standard Network Security appliance:

    • The appliance continues to detect malware. Additional MVX-verified malware (malware alerts) continue to appear in the Hosts tab and the Alerts tab.

    • The platform no longer detects IPS events. No additional MVX-correlated IPS events (IPS alerts) appear in the Hosts tab, the Alerts tab, or IPS Events page.

  5. Save your changes.

    hostname (config) # write memory