This URL updates IPS policy.
Resource URL
PUT /ipspolicy/<policyid>
Request Parameters
URL Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Policy id | Number | Yes |
Payload Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Policy name | String | Yes (Custom policy) No (Default policy) |
| Policy description | String | No |
| Is policy visible to child domain | Boolean | No |
| Rule set with inbound direction | String | Yes (Custom policy) No (Default policy) |
| Rule set with outbound direction | String | Yes (Custom policy) No (Default policy) |
| Reconnaissance policy attack list | Object | No |
| Attack category | Object | No |
| Outbound attack category | Object | Yes NoteThe value can be empty if no update is required. However, the key should be present in the payload. |
| DOS policy | Object | No |
| DOS response sensitivity level value can be:
| Number | No |
| Is policy editable after creation | Boolean | No |
| Consider inbound/outbound direction values can be:
| Number | No |
Details of object in AttackCategory:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| List of exploit attacks | Array | No |
Details of object in ExpolitAttackList:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| NSP id of the attack | String | No |
| Attack severity between 0 and 9 | Number | No |
| Is attack severity customized | Boolean | No |
| Is attack enabled | Boolean | No |
| Is alert customized | Boolean | No Note
|
| Is attack recommended for smart blocking | Boolean | No |
| Attack response | Object | No |
| Notifications configured | Object | Yes NoteThe value can be empty if no update is required. However, the key should be present in the payload. |
| List of protocols | Array | No |
| Attack benign trigger probability | String | No |
| Attack target, can be server or client | String | No |
| Blocking type, can be attack packet | String | No |
| Attack sub category | String | No |
| Attack direction can be inbound, outbound, or both | String | No |
Details of object in AttackResponse:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| TCP reset option, can be
| String | No |
| Is TCP reset customized | Boolean | No |
| Send ICMP host unreachable to source | Boolean | No |
| Send ICMP host unreachable to source customized | Boolean | No |
| NAC notification configured, can be
| String | No |
| Is NAC notification enabled | Boolean | No |
| Is quarantine customized | Boolean | No |
| Is remediate enabled | Boolean | No |
| Blocking option configured, can be
| String | No |
| Is blocking option customized | Boolean | No |
| Should application data be captured before an attack | Boolean | No |
| Should application data be captured before attack customized | Boolean | No |
| If action is customized set it as true | Boolean | No |
| Action to be taken on attack, can be
| String | No |
| Is logging customized | Boolean | No |
| Customize flow, can be
| String | No |
| Customize flow type | Boolean | No |
| Is logging N number of bytes in each packet customized | Boolean | No |
| Number of bytes to be logged in each packet | Object | No |
| Packet logging duration | Object | No |
Details of object in numberOfBytesInEachPacket (Can be either of the below mentioned):
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| log entire packet | Object | No |
| Capture N number of bytes | Object | No |
Details of object in CaptureNBytes:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Number of bytes to log | Number | No |
Details of object in loggingDuration (Can be either of the below mentioned):
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Log attack packet only | Object | No |
| Capture N packets | Object | No |
| Capture for a time duration | Object | No |
| Capture rest of flow | Object | No |
Details of object in CaptureNPackets:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Log n packets | Number | No |
Details of object in CaptureTimeDuration:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Capture time | String | No |
| Time unit, can be
| String | No |
Details of object in notification:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Is notification configured through email | Boolean | No |
| Is notification configured through pager | Boolean | No |
| Is notification configured through script | Boolean | No |
| Is notification configured through auto acknowledge | Boolean | No |
| Is notification configured through SNMP | Boolean | No |
| Is notification configured through Syslog | Boolean | No |
| Is notification through email customized | Boolean | No |
| Is notification through pager customized | Boolean | No |
| Is notification through script customized | Boolean | No |
| Is notification through auto acknowledge customized | Boolean | No |
| Is notification through SNMP customized | Boolean | No |
| Is notification through Syslog customized | Boolean | No |
Details of object in DosPolicy:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| List of learning attacks | Array | No |
| List of threshold attacks | Array | No |
| Time stamp | String | No |
Details of object in LearningAttack:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Attack name | String | No |
| NSP ID of the attack | String | No |
| Is the attack severity customized | Boolean | No |
| Attack severity between 0 and 9 | Number | No |
| Is blocking customized | Boolean | No |
| Drop DOS attack packets of this attack type when detected | Boolean | No |
| Is alert customized | Boolean | No |
| Is alert notification to be sent to the Manager configured | Boolean | No |
| Attack direction can be:
| String | No |
| Specifies the Manager's action for the attack | Object | Yes NoteThe value can be empty if no update is required. However, the key should be present in the payload. |
Details of object in ThresholdAttack:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Attack name | String | No |
| NSP ID of the attack | String | No |
| Is the attack severity customized | Boolean | No |
| Attack severity between 0 and 9 | Number | No |
| Is threshold value customized | Boolean | No |
| Is threshold duration customized | Boolean | No |
| Threshold value | Number | No |
| Threshold interval (seconds) | Number | No |
| Is alert customized | Boolean | No |
| Is alert notification to be sent to the Manager configured | Boolean | No |
| Specifies the Manager's action for the attack | Object | Yes NoteThe value can be empty if no update is required. However, the key should be present in the payload. |
| Attack direction can be:
| String | No |
Details of object in ReconAttack List:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Is alert customized | Boolean | No |
| NSP ID of the attack | String | No |
| Is the attack severity customized | Boolean | No |
| Attack severity between 0 and 9 | Number | No |
| Threshold value | Number | No |
| Is remediate enabled | Boolean | No |
| Is alert customized | Boolean | No |
| Is alert notification to be sent to the Manager configured | Boolean | No |
| Threshold interval (seconds) | Number | No |
| Alert suppression timer | Number | No |
| Is alert suppression timer customized | Boolean | No |
| Is NAC notification enabled | Boolean | No |
| NAC notification configured, can be
| String | No |
| Specifies the Manager's action for the attack. | Object | Yes NoteThe value can be empty if no update is required. However, the key should be present in the payload. |
| Is quarantine customized | Boolean | No |
| Is threshold duration customized | Boolean | No |
Response Parameters
Following fields are returned if the operation was successful, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| Status of the request | Number |
Example
Request
PUT https://<NSM_IP>/sdkapi/ipspolicy/<policyid>
Payload:
{
"DosResponseSensitivityLevel": 1,
"direction": 1,
"Description": "Updated policy",
"IsEditable": true,
"PolicyName": "ipstest",
"ReconPolicy": {
"ReconAttackList": [
{
"IsAlertCustomized": true,
"isQuarantineCustomized": true,
"severity": 6,
"isThresholdDurationCustomized": true,
"isEnabled": true,
"isSendAlertToManager": true,
"nspId": "0x43f00900",
"ThresholdDuration": 5,
"alertSuppressionTimer": 5,
"isAlertSuppressionTimerCustomized": true,
"isMcAfeeNACNotificationEnabled": true,
"ThresholdValue": 200,
"notification": {
"isAutoAckCustomized": true,
"isPager": true,
"isSyslogCustomized": true,
"isPagerCustomized": true,
"isEmail": true,
"isScriptCustomized": true,
"isSnmpCustomized": true,
"isScript": true,
"isSnmp": true,
"isEmailCustomized": true,
"isAutoAck": true,
"isSyslog": true
},
"mcAfeeNACNotification": "ALL_HOSTS",
"isRemediateEnabled": true,
"isSeverityCustomized": true,
"isThresholdValueCustomized": true
}
]
},
"DosPolicy": {
"LearningAttack": [
{
"IsAlertCustomized": true,
"direction": "INBOUND",
"severity": 7,
"isDropPacket": false,
"isSendAlertToManager": true,
"nspId": "0x4000b600",
"isBlockingSettingCustomized": true,
"attackName": "Inbound IP Fragment Volume Too High",
"isSeverityCustomized": true,
"notification": {
"isAutoAckCustomized": true,
"isPager": true,
"isSyslogCustomized": true,
"isPagerCustomized": true,
"isEmail": true,
"isScriptCustomized": true,
"isSnmpCustomized": true,
"isScript": true,
"isSnmp": true,
"isEmailCustomized": true,
"isAutoAck": true,
"isSyslog": true
}
}
],
"ThresholdAttack": [
{
"isAlertCustomized": true,
"direction": "INBOUND",
"severity": 6,
"isThresholdDurationCustomized": true,
"isSendAlertToManager": true,
"nspId": "0x40018300",
"ThresholdDuration": 5,
"isSeverityCustomized": true,
"Notification": {
"isAutoAckCustomized": true,
"isPager": true,
"isSyslogCustomized": true,
"isPagerCustomized": true,
"isEmail": true,
"isScriptCustomized": true,
"isSnmpCustomized": true,
"isScript": true,
"isSnmp": true,
"isEmailCustomized": true,
"isAutoAck": true,
"isSyslog": true
},
"attackName": "Too Many Outbound ICMP Packets",
"ThresholdValue": 200,
"isThresholdValueCustomized": true
}
]
},
"IsVisibleToChildren": true,
"OutboundAttackCategory": {
"ExpolitAttackList": [
{
"isAlertCustomized": true,
"blockingType": "attack-packet",
"direction": "OUTBOUND",
"severity": 5,
"AttackResponse": {
"isFlowCustomized": true,
"isICMPSend": true,
"blockingOption": "DISABLE",
"mcAfeeNACNotification": "DISABLED",
"isAlertCustomized": true,
"isCapturedPrior": true,
"numberOfBytesInEachPacket": {
"CaptureNBytes": {
"NumberOfBytes": 5
},
"LogEntirePacket": {}
},
"isICMPSendCustomized": true,
"isCapturedPriorCustomized": true,
"TimeStamp": "None",
"isQuarantineCustomized": true,
"TCPReset": "BOTH",
"isLogCustomized": true,
"isTcpResetCustomized": true,
"isNbytesCustomized": true,
"flow": "SINGLE_FLOW",
"isMcAfeeNACNotificationEnabled": false,
"isAlert": true,
"action": "SEND_ALERT_AND_LOG_PACKETS",
"loggingDuration": {
"CaptureNPackets": {
"npackets": 5
},
"AttackPacketOnly": {},
"RestOfFlow": null,
"CaptureTimeDuration": {
"timeUnit": "SECONDS",
"time": "10"
}
},
"isRemediateEnabled": true,
"isBlockingOptionCustomized": true
},
"nspId": "0x40254c00",
"isEnabled": true,
"benignTriggerProbability": "1 (Low)",
"notification": {
"isAutoAckCustomized": true,
"isPager": true,
"isSyslogCustomized": true,
"isPagerCustomized": true,
"isEmail": true,
"isScriptCustomized": true,
"isSnmpCustomized": true,
"isScript": true,
"isSnmp": true,
"isEmailCustomized": true,
"isAutoAck": true,
"isSyslog": true
},
"isRecommendedForSmartBlocking": true,
"isSeverityCustomized": true,
"subCategory": "dos"
}
]
},
"AttackCategory": {
"ExpolitAttackList": [
{
"isAlertCustomized": true,
"blockingType": "attack-packet",
"direction": "INBOUND",
"severity": 5,
"AttackResponse": {
"isFlowCustomized": true,
"isICMPSend": true,
"blockingOption": "DISABLE",
"mcAfeeNACNotification": "DISABLED",
"isAlertCustomized": true,
"isCapturedPrior": true,
"numberOfBytesInEachPacket": {
"CaptureNBytes": {
"NumberOfBytes": 5
},
"LogEntirePacket": {}
},
"isICMPSendCustomized": true,
"isCapturedPriorCustomized": true,
"TimeStamp": "None",
"isQuarantineCustomized": true,
"TCPReset": "BOTH",
"isLogCustomized": true,
"isTcpResetCustomized": true,
"isNbytesCustomized": true,
"flow": "SINGLE_FLOW",
"isMcAfeeNACNotificationEnabled": false,
"isAlert": true,
"action": "SEND_ALERT_AND_LOG_PACKETS",
"loggingDuration": {
"CaptureNPackets": {"npackets": 5},
"AttackPacketOnly": {},
"RestOfFlow": null,
"CaptureTimeDuration": {
"timeUnit": "SECONDS",
"time": "10"
}
},
"isRemediateEnabled": true,
"isBlockingOptionCustomized": true
},
"nspId": "0x40254c00",
"isEnabled": true,
"benignTriggerProbability": "1 (Low)",
"notification": {
"isAutoAckCustomized": true,
"isPager": true,
"isSyslogCustomized": true,
"isPagerCustomized": true,
"isEmail": true,
"isScriptCustomized": true,
"isSnmpCustomized": true,
"isScript": true,
"isSnmp": true,
"isEmailCustomized": true,
"isAutoAck": true,
"isSyslog": true
},
"isRecommendedForSmartBlocking": true,
"isSeverityCustomized": true,
"subCategory": "dos"
}
]
},
"OutboundRuleSet": "DMZ",
"InboundRuleSet": "Default Prevention"
}
Important
To enable ReconPolicy or DosPolicy in IPS policies via API, the field "isSendAlertToManager" must be set to true.
Response
{
status :1
}