fenotify preferences ips-delivery-mode

Prev Next

To configure when IPS event notifications are delivered, use the fenotify preferences ips‑delivery‑mode command in configuration mode. This command applies only to IPS-enabled appliances on which you have enabled IPS event notifications services and configured IPS event notification methods.

Syntax

fenotify preferences ops-delivery-mode <mode>

User role

Admin or Operator

Supported appliances

Command introduced in Release 7.5.0 for IPS-enabled appliances only.

Description

Configures when IPS event notifications are delivered. For more information, see the Network Security IPS Feature Guide.

Parameters

mode

Specify the delivery mode for IPS event notifications:

  • instant—Send only when an IPS event is detected. This is the default value.

  • confirmation—Send only when an attack has been confirmed (either positive or negative).

  • dual—Send both when an IPS event is detected and when an attack has been confirmed.

By default, the system is configured to use instant delivery mode, which is useful in an organization that archives notifications and then filters and analyzes the information later. When you first activate IPS features, we recommend that you use dual mode so that you see both detection and confirmation of IPS events. If your organization does not archive the volume of notifications generated in this mode, you can decrease the volume of notifications by using confirmation mode.

Example

hostname (config) # fenotify preferences ips dual