The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update IPS Policy

Prev Next

This URL updates IPS policy.

Resource URL

PUT /ipspolicy/<policyid>

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

policyId

Policy id

Number

Yes

Payload Parameters:

Field Name

Description

Data Type

Mandatory

PolicyName

Policy name

String

Yes (Custom policy)

No (Default policy)

Description

Policy description

String

No

IsVisibleToChildren

Is policy visible to child domain

Boolean

No

InboundRuleSet

Rule set with inbound direction

String

Yes (Custom policy)

No (Default policy)

OutboundRuleSet

Rule set with outbound direction

String

Yes (Custom policy)

No (Default policy)

ReconPolicy

Reconnaissance policy attack list

Object

No

AttackCategory

Attack category

Object

No

OutboundAttackCategory

Outbound attack category

Object

Yes

Note

The value can be empty if no update is required. However, the key should be present in the payload.

DosPolicy

DOS policy

Object

No

DosResponseSensitivityLevel

DOS response sensitivity level value can be:

  • 0

  • 1

Number

No

isEditable

Is policy editable after creation

Boolean

No

direction

Consider inbound/outbound direction values can be:

  • 0

  • 1

Number

No

Details of object in AttackCategory:

Field Name

Description

Data Type

Mandatory

ExpolitAttackList

List of exploit attacks

Array

No

Details of object in ExpolitAttackList:

Field Name

Description

Data Type

Mandatory

nspId

NSP id of the attack

String

No

severity

Attack severity between 0 and 9

Number

No

isSeverityCustomized

Is attack severity customized

Boolean

No

isEnabled

Is attack enabled

Boolean

No

isAlertCustomized

Is alert customized

Boolean

No

Note

isAlertCustomized should be set to true for changing the isEnabled field.

isRecommendedForSmartBlocking

Is attack recommended for smart blocking

Boolean

No

AttackResponse

Attack response

Object

No

notification

Notifications configured

Object

Yes

Note

The value can be empty if no update is required. However, the key should be present in the payload.

protocolList

List of protocols

Array

No

benignTriggerProbability

Attack benign trigger probability

String

No

target

Attack target, can be server or client

String

No

blockingType

Blocking type, can be attack packet

String

No

subCategory

Attack sub category

String

No

direction

Attack direction can be inbound, outbound, or both

String

No

Details of object in AttackResponse:

Field Name

Description

Data Type

Mandatory

TCPReset

TCP reset option, can be

  • Disabled source

  • Disabled destination

  • Both

String

No

isTCPResetCustomized

Is TCP reset customized

Boolean

No

isICMPSend

Send ICMP host unreachable to source

Boolean

No

isICMPSendCustomized

Send ICMP host unreachable to source customized

Boolean

No

mcafeeNACNotification

NAC notification configured, can be

  • Disabled

  • All hosts

  • McAfee NAC unmanaged hosts

String

No

isMcafeeNACNotificationEnabled

Is NAC notification enabled

Boolean

No

isQuarantineCustomized

Is quarantine customized

Boolean

No

isRemediateEnabled

Is remediate enabled

Boolean

No

blockingOption

Blocking option configured, can be

  • Disable

  • Enable

  • Enable smart blocking

String

No

isBlockingOptionCustomized

Is blocking option customized

Boolean

No

isCapturedPrior

Should application data be captured before an attack

Boolean

No

isCapturedPriorCustomized

Should application data be captured before attack customized

Boolean

No

isAlert

If action is customized set it as true

Boolean

No

action

Action to be taken on attack, can be

  • Do nothing

  • Send alert and log packets

  • Send alert only

String

No

isLogCustomized

Is logging customized

Boolean

No

flow

Customize flow, can be

  • Single flow

  • Forensic analysis

String

No

isFlowCustomized

Customize flow type

Boolean

No

isNbytesCustomized

Is logging N number of bytes in each packet customized

Boolean

No

numberOfBytesInEachPacket

Number of bytes to be logged in each packet

Object

No

loggingDuration

Packet logging duration

Object

No

Details of object in numberOfBytesInEachPacket (Can be either of the below mentioned):

Field Name

Description

Data Type

Mandatory

LogEntirePacket

log entire packet

Object

No

CaptureNBytes

Capture N number of bytes

Object

No

Details of object in CaptureNBytes:

Field Name

Description

Data Type

Mandatory

NumberOfBytes

Number of bytes to log

Number

No

Details of object in loggingDuration (Can be either of the below mentioned):

Field Name

Description

Data Type

Mandatory

AttackPacketOnly

Log attack packet only

Object

No

CaptureNPackets

Capture N packets

Object

No

CaptureTimeDuration

Capture for a time duration

Object

No

RestOfFlow

Capture rest of flow

Object

No

Details of object in CaptureNPackets:

Field Name

Description

Data Type

Mandatory

npackets

Log n packets

Number

No

Details of object in CaptureTimeDuration:

Field Name

Description

Data Type

Mandatory

time

Capture time

String

No

timeUnit

Time unit, can be

  • Seconds

  • Minutes

  • Hours

  • Days

String

No

Details of object in notification:

Field Name

Description

Data Type

Mandatory

isEmail

Is notification configured through email

Boolean

No

isPager

Is notification configured through pager

Boolean

No

isScript

Is notification configured through script

Boolean

No

isAutoAck

Is notification configured through auto acknowledge

Boolean

No

isSnmp

Is notification configured through SNMP

Boolean

No

isSyslog

Is notification configured through Syslog

Boolean

No

isEmailCustomized

Is notification through email customized

Boolean

No

isPagerCustomized

Is notification through pager customized

Boolean

No

isScriptCustomized

Is notification through script customized

Boolean

No

isAutoAckCustomized

Is notification through auto acknowledge customized

Boolean

No

isSnmpCustomized

Is notification through SNMP customized

Boolean

No

isSyslogCustomized

Is notification through Syslog customized

Boolean

No

Details of object in DosPolicy:

Field Name

Description

Data Type

Mandatory

LearningAttack

List of learning attacks

Array

No

ThresholdAttack

List of threshold attacks

Array

No

TimeStamp

Time stamp

String

No

Details of object in LearningAttack:

Field Name

Description

Data Type

Mandatory

attackName

Attack name

String

No

nspId

NSP ID of the attack

String

No

isSeverityCustomized

Is the attack severity customized

Boolean

No

severity

Attack severity between 0 and 9

Number

No

isBlockingSettingCustomized

Is blocking customized

Boolean

No

isDropPacket

Drop DOS attack packets of this attack type when detected

Boolean

No

isAlertCustomized

Is alert customized

Boolean

No

isSendAlertToManager

Is alert notification to be sent to the Manager configured

Boolean

No

direction

Attack direction can be:

  • Inbound

  • Outbound

  • Inbound and outbound

String

No

notification

Specifies the Manager's action for the attack

Object

Yes

Note

The value can be empty if no update is required. However, the key should be present in the payload.

Details of object in ThresholdAttack:

Field Name

Description

Data Type

Mandatory

attackName

Attack name

String

No

nspId

NSP ID of the attack

String

No

isSeverityCustomized

Is the attack severity customized

Boolean

No

severity

Attack severity between 0 and 9

Number

No

isThresholdValueCustomized

Is threshold value customized

Boolean

No

isThresholdDurationCustomized

Is threshold duration customized

Boolean

No

ThresholdValue

Threshold value

Number

No

ThresholdDuration

Threshold interval (seconds)

Number

No

isAlertCustomized

Is alert customized

Boolean

No

isSendAlertToManager

Is alert notification to be sent to the Manager configured

Boolean

No

notification

Specifies the Manager's action for the attack

Object

Yes

Note

The value can be empty if no update is required. However, the key should be present in the payload.

direction

Attack direction can be:

  • Inbound

  • Outbound

  • Inbound and outbound

String

No

Details of object in ReconAttack List:

Field Name

Description

Data Type

Mandatory

isAlertCustomized

Is alert customized

Boolean

No

nspId

NSP ID of the attack

String

No

isSeverityCustomized

Is the attack severity customized

Boolean

No

severity

Attack severity between 0 and 9

Number

No

ThresholdValue

Threshold value

Number

No

isRemediateEnabled

Is remediate enabled

Boolean

No

isAlertCustomized

Is alert customized

Boolean

No

isSendAlertToManager

Is alert notification to be sent to the Manager configured

Boolean

No

ThresholdDuration

Threshold interval (seconds)

Number

No

alertSuppressionTimer

Alert suppression timer

Number

No

isAlertSuppressionTimerCustomized

Is alert suppression timer customized

Boolean

No

isMcafeeNACNotificationEnabled

Is NAC notification enabled

Boolean

No

mcafeeNACNotification

NAC notification configured, can be

  • Disabled

  • All hosts

  • McAfee NAC unmanaged hosts

String

No

notification

Specifies the Manager's action for the attack.

Object

Yes

Note

The value can be empty if no update is required. However, the key should be present in the payload.

isQuarantineCustomized

Is quarantine customized

Boolean

No

isThresholdDurationCustomized

Is threshold duration customized

Boolean

No

Response Parameters

Following fields are returned if the operation was successful, otherwise error details are returned.

Field Name

Description

Data Type

status

Status of the request

Number

Example

Request

PUT https://<NSM_IP>/sdkapi/ipspolicy/<policyid>

Payload:

{
	"DosResponseSensitivityLevel": 1, 
	"direction": 1, 
	"Description": "Updated policy", 
	"IsEditable": true, 
	"PolicyName": "ipstest", 
	"ReconPolicy": {
		"ReconAttackList": [
			{
				"IsAlertCustomized": true, 
				"isQuarantineCustomized": true, 
				"severity": 6, 
				"isThresholdDurationCustomized": true,
                "isEnabled": true, 
				"isSendAlertToManager": true, 
				"nspId": "0x43f00900", 
				"ThresholdDuration": 5, 
				"alertSuppressionTimer": 5, 
				"isAlertSuppressionTimerCustomized": true, 
				"isMcAfeeNACNotificationEnabled": true, 
				"ThresholdValue": 200, 
				"notification": {
					"isAutoAckCustomized": true, 
					"isPager": true, 
					"isSyslogCustomized": true, 
					"isPagerCustomized": true, 
					"isEmail": true, 
					"isScriptCustomized": true, 
					"isSnmpCustomized": true, 
					"isScript": true, 
					"isSnmp": true, 
					"isEmailCustomized": true, 
					"isAutoAck": true, 
					"isSyslog": true
				}, 
				"mcAfeeNACNotification": "ALL_HOSTS", 
				"isRemediateEnabled": true, 
				"isSeverityCustomized": true, 
				"isThresholdValueCustomized": true
			}
		]
	}, 
	"DosPolicy": {
		"LearningAttack": [
			{
				"IsAlertCustomized": true, 
				"direction": "INBOUND", 
				"severity": 7, 
				"isDropPacket": false, 
				"isSendAlertToManager": true, 
				"nspId": "0x4000b600", 
				"isBlockingSettingCustomized": true, 
				"attackName": "Inbound IP Fragment Volume Too High", 
				"isSeverityCustomized": true, 
				"notification": {
					"isAutoAckCustomized": true, 
					"isPager": true, 
					"isSyslogCustomized": true, 
					"isPagerCustomized": true, 
					"isEmail": true, 
					"isScriptCustomized": true, 
					"isSnmpCustomized": true, 
					"isScript": true, 
					"isSnmp": true, 
					"isEmailCustomized": true, 
					"isAutoAck": true, 
					"isSyslog": true
				}
			}
		], 
		"ThresholdAttack": [
			{
				"isAlertCustomized": true, 
				"direction": "INBOUND", 
				"severity": 6, 
				"isThresholdDurationCustomized": true, 
				"isSendAlertToManager": true, 
				"nspId": "0x40018300", 
				"ThresholdDuration": 5, 
				"isSeverityCustomized": true, 
				"Notification": {
					"isAutoAckCustomized": true, 
					"isPager": true, 
					"isSyslogCustomized": true, 
					"isPagerCustomized": true, 
					"isEmail": true, 
					"isScriptCustomized": true, 
					"isSnmpCustomized": true, 
					"isScript": true, 
					"isSnmp": true, 
					"isEmailCustomized": true, 
					"isAutoAck": true, 
					"isSyslog": true
				}, 
				"attackName": "Too Many Outbound ICMP Packets", 
				"ThresholdValue": 200, 
				"isThresholdValueCustomized": true
			}
		]
	}, 
	"IsVisibleToChildren": true, 
	"OutboundAttackCategory": {
		"ExpolitAttackList": [
			{
				"isAlertCustomized": true, 
				"blockingType": "attack-packet", 
				"direction": "OUTBOUND", 
				"severity": 5, 
				"AttackResponse": {
					"isFlowCustomized": true, 
					"isICMPSend": true, 
					"blockingOption": "DISABLE", 
					"mcAfeeNACNotification": "DISABLED", 
					"isAlertCustomized": true, 
					"isCapturedPrior": true, 
					"numberOfBytesInEachPacket": {
						"CaptureNBytes": {
							"NumberOfBytes": 5
							}, 
						"LogEntirePacket": {}
					}, 
					"isICMPSendCustomized": true, 
					"isCapturedPriorCustomized": true, 
					"TimeStamp": "None", 
					"isQuarantineCustomized": true, 
					"TCPReset": "BOTH", 
					"isLogCustomized": true, 
					"isTcpResetCustomized": true, 
					"isNbytesCustomized": true, 
					"flow": "SINGLE_FLOW", 
					"isMcAfeeNACNotificationEnabled": false, 
					"isAlert": true, 
					"action": "SEND_ALERT_AND_LOG_PACKETS", 
					"loggingDuration": {
						"CaptureNPackets": {
							"npackets": 5
						}, 
						"AttackPacketOnly": {}, 
						"RestOfFlow": null, 
						"CaptureTimeDuration": {
							"timeUnit": "SECONDS", 
							"time": "10"
						}
					}, 
					"isRemediateEnabled": true, 
					"isBlockingOptionCustomized": true
				}, 
				"nspId": "0x40254c00", 
				"isEnabled": true, 
				"benignTriggerProbability": "1 (Low)", 
				"notification": {
					"isAutoAckCustomized": true, 
					"isPager": true, 
					"isSyslogCustomized": true, 
					"isPagerCustomized": true, 
					"isEmail": true, 
					"isScriptCustomized": true, 
					"isSnmpCustomized": true, 
					"isScript": true, 
					"isSnmp": true, 
					"isEmailCustomized": true, 
					"isAutoAck": true, 
					"isSyslog": true
				}, 
				"isRecommendedForSmartBlocking": true, 
				"isSeverityCustomized": true, 
				"subCategory": "dos"
			}
		]
	}, 
	"AttackCategory": {
		"ExpolitAttackList": [
			{
				"isAlertCustomized": true, 
				"blockingType": "attack-packet", 
				"direction": "INBOUND", 
				"severity": 5, 
				"AttackResponse": {
					"isFlowCustomized": true, 
					"isICMPSend": true, 
					"blockingOption": "DISABLE", 
					"mcAfeeNACNotification": "DISABLED", 
					"isAlertCustomized": true, 
					"isCapturedPrior": true, 
					"numberOfBytesInEachPacket": {
						"CaptureNBytes": {
							"NumberOfBytes": 5
						}, 
						"LogEntirePacket": {}
					}, 
					"isICMPSendCustomized": true, 
					"isCapturedPriorCustomized": true, 
					"TimeStamp": "None", 
					"isQuarantineCustomized": true, 
					"TCPReset": "BOTH", 
					"isLogCustomized": true, 
					"isTcpResetCustomized": true, 
					"isNbytesCustomized": true, 
					"flow": "SINGLE_FLOW", 
					"isMcAfeeNACNotificationEnabled": false, 
					"isAlert": true, 
					"action": "SEND_ALERT_AND_LOG_PACKETS", 
					"loggingDuration": {
						"CaptureNPackets": {"npackets": 5}, 
						"AttackPacketOnly": {}, 
						"RestOfFlow": null, 
						"CaptureTimeDuration": {
							"timeUnit": "SECONDS", 
							"time": "10"
						}
					}, 
					"isRemediateEnabled": true, 
					"isBlockingOptionCustomized": true
				}, 
				"nspId": "0x40254c00", 
				"isEnabled": true, 
				"benignTriggerProbability": "1 (Low)", 
				"notification": {
					"isAutoAckCustomized": true, 
					"isPager": true, 
					"isSyslogCustomized": true, 
					"isPagerCustomized": true, 
					"isEmail": true, 
					"isScriptCustomized": true, 
					"isSnmpCustomized": true, 
					"isScript": true, 
					"isSnmp": true, 
					"isEmailCustomized": true, 
					"isAutoAck": true, 
					"isSyslog": true
				}, 
				"isRecommendedForSmartBlocking": true, 
				"isSeverityCustomized": true, 
				"subCategory": "dos"
			}
		]
	}, 
	"OutboundRuleSet": "DMZ", 
	"InboundRuleSet": "Default Prevention"
}

Important

To enable ReconPolicy or DosPolicy in IPS policies via API, the field "isSendAlertToManager" must be set to true.

Response

{
status :1
}