Delete an alert policy exception for the alert rules that address aspects of the specified signature name.
Syntax
no policymgr signature name <nameID> [interface {<portPair> | ALL | MGMT} [src {<srcIP>/<prefix> | any} [ dst {<dstIP>/<prefix> | any}]]]
Parameters
<nameID>
Delete an exception for the alert rules that address aspects of the specified signature name.
interface {<portPair> | ALL | MGMT}
The exception to be deleted applies to traffic through the specified appliance interface:
<portPair>—Traffic through the specified monitoring port pair. See the Hardware Administration Guide for your appliance.ALL—Traffic through all monitoring port pairs.MGMT—Traffic through the appliance management interface.
src {<srcIP>/<prefix> | any}
The exception to be deleted applies to traffic with the specified source.
<srcIP>/<prefix>—Traffic with the specified source IPv4 host or subnet, specified in CIDR format. Example: 10.128.45.154/32<any>—Traffic with any source IPv4 address.
dst {<dstIP>/<prefix> | any}
The exception to be deleted applies to traffic with the specified destination.
<dstIP>/<prefix>—Traffic with the specified destination IPv4 host or subnet, specified in CIDR format. Example: 172.217.27.36/32<any>—Traffic with any destination IPv4 address.
Example
This example deletes an alert policy exception for the alert rules specified by signature name Downloader.Locky. The exception being deleted applies to traffic through the appliance monitoring port pair A, with the 10.128.45.154/32 subnet source and the 172.217.27.36/32 subnet destination.
hostname (config) # no policymgr signature name Downloader.Locky interface A src 10.128.45.154/32 dst 172.217.27.36/32
User role
Operator or Admin
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Release 9.0.2