The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Suppressing an IPS brute-force rule (Web UI)

Prev Next

You can suppress an IPS brute-force rule.

Prerequisites
  • Log in to the Web UI of the IPS appliance as Analyst or Admin.

Procedure

To suppress an IPS rule for brute-force attacks:

  1. Choose IPS > IPS Events.

  2. Locate the brute-force event entry type to suppress. See Showing or hiding or brute-force events (Web UI).

  3. Make note of the name of the IPS rule that detected these brute-force events. The rule name is displayed in the Rule field.

  4. Click the plus icon (ctrl_ips_add.png) in the left column of that row to open the drill-down view.

  5. Click Add Exception Rule. Use the Adding a Signature Exception wizard to guide you through the steps to suppress a vulnerability or IPS rule from a particular IP address.

    scap_ips_events_brute-force_suppress_rule_ip.png

  6. In the Signature step of the wizard, select the suppression at a per-rule level or at a per-vulnerability level. Choose Signature Id, Signature Name, or Signature Id & Name. Click Next or Interface.

  7. In the Interface step of the wizard, select ALL Interfaces. Click Next or Victim IP.

  8. In the Victim IP step of the wizard, verify the particular destination (victim) IP address and the subnet mask. Click Next or Attacker IP and Action.

  9. In the Attacker IP and Action step of the wizard, verify the particular source (attacker) IP address and the subnet mask. Choose the action Suppress.

  10. Click Save.