The IPS profile can include protections that are not necessary for the network. You can exclude unnecessary IPS protections for the application or service and improve network performance. For example, if an organization does not use VoIP services, exclude the IPS protections for VoIP traffic.
IPS Protections are classified into categories of applications and protocols that they protect. If there are applications that are not used in the network, you can exclude the appropriate category of IPS protections.
To exclude an IPS category:
The Profiles window opens.
The General page of the Profile Properties window opens.
The Non-Auto Activation window opens.
Often it is not possible to exclude an entire category of IPS protections. However, you can still exclude individual protections for:
To safely exclude protections, make sure that you have all the data about the applications and services that run in the network. It must be up-to-date, and include data about software versions and patches.
To exclude a specified IPS protection:
The Network Exceptions window opens.
The Add/Edit Exception Rule window opens.
The Select Protection window opens.