You can remove IPS policies from all interfaces in a single step instead of removing policies individually from each interface. Without IPS policies applied to monitoring interfaces, the platform functions as a standard Network Security appliance that detects and, if deployed and configured inline, can block client-centric HTTP-based malware.
To delete a custom IPS policy definition from an IPS platform, see Deleting a custom IPS policy (CLI).
Prerequisites
Log in to the CLI of the IPS platform as Operator or Admin.
Procedure
To stop applying policy-selected IPS rules to the traffic at all interfaces:
Enable the CLI configuration mode.
hostname > enable hostname # configure terminalDisplay the appliance interfaces and the current application of IPS policies to appliance interfaces.
In the following example, the appliance has two interfaces and two default IPS policies are active on the interfaces.
hostname (config) # show ips interfaces Interface : A Policy applied : FireEye_Default Rule count : 2640 Interface : B Policy applied : Comprehensive Rule count : 6882Remove all IPS policies from all interfaces.
hostname (config) # no ips apply allConfirm your configuration changes.
hostname (config) # show ips interfaces Interface : A Policy applied : empty Rule count : 0 Interface : B Policy applied : empty Rule count : 0Without IPS policies applied to interfaces, the platform functions as a standard Network Security appliance:
The appliance continues to detect malware. Additional MVX-verified malware (malware alerts) continue to appear in the Hosts tab and the Alerts tab.
The platform no longer detects IPS events. No additional MVX-correlated IPS events (IPS alerts) appear in the Hosts tab, the Alerts tab, or IPS Events page.
Save your changes.
hostname (config) # write memory