ips apply

Prev Next

Applies or removes an IPS policy on a monitoring interface.

You can apply the rule-selection criteria (match attributes, exclusion list, and inclusion list) of the specified IPS policy to the network traffic passing through the specified monitoring interface. The system automatically sets the value of the policy's active attribute to yes. If a different IPS policy was already active on the interfaces, the system automatically removes that policy from the interfaces before applying the new policy.

For more information, see the Network Security IPS Feature Guide.

Note

You can also run this command remotely from the command line of an integrated Central Management System appliance using the central management appliance proxying mechanism.

Syntax

[no] ips apply {all | <policyName> interface <interfaceName>}

Parameters

no

Use the no form of the command to explicitly remove the specified IPS policy from the specified monitoring interface or to remove all IPS policies from all interfaces. When the interface is not associated with an IPS policy, traffic that passes through the interface is analyzed using standard Network Security content rules only.

all

Remove all IPS policies from all monitoring interfaces. Supported for the no form of the command only.

<policyName>

Name of the IPS policy to apply to monitoring interfaces on the Network Security appliance.

interface <interfaceName>

Apply the specified policy to the specified monitoring interface:

  • A—Monitoring interfaces labeled pether3 and pether4.

  • B—Monitoring interfaces labeled pether5 and pether6 (on appliances with two port pairs).

Examples

ips apply Trellix_Default interface A
hostname (config) # ips apply Trellix_Default interface A
ips apply Default_Server_Protection interface B
hostname (config) # ips apply Default_Server_Protection interface B
no ips apply Default_Server_Protection interface B
hostname (config) # no ips apply Default_Server_Protection interface B

User role

Operator or Admin

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 7.2.0