Network Security alert policy exceptions

Prev Next

An alert policy exception enables you to override the actions defined in alert rules. You can configure an alert policy exception for a signature ID, a signature name, an attack category, or all signatures. An alert policy exception can apply to a single monitoring port pair, all monitoring port pairs, or to the appliance management interface. The scope of an alert policy exception can be refined by source IP address or destination IP address. Alert policy exceptions are supported in IPv4 networks only, and they support signatures for the following types of attacks: Infection Match, Malware Callback, Riskware, IPS, Reconnaissance, or Local Signature.

Note

This feature replaces Inline policy exceptions and IPS policy exceptions.

API definitions

The commands are available on the following appliance:

  • Network Security

  • Version supported is 2.0.0

  • The IPS API base URI is https://<host>/wsapi/v2.0.0/config/network (represented as <network-api-base> in the table).

  • Standard WSAPI authentication and RBAC are used