Configuring IPS Profile Settings

Additional Activation Fields

For additional granularity, in the Additional Activation section of the Profile configuration window, you can select IPS protections to activate and to deactivate. The IPS protections are arranged into tags (categories) such as Product, Vendor, Threat Year, and others, for the ease of search. The gateways enforce activated protections, and do not enforce deactivated protections, regardless of the general profile protection settings.

  • Activate IPS protections according to the following additional properties - When selected, the categories configured on this page modify the profile's IPS protections.

    • Protections to activate - The IPS protection categories in this section are enabled on the Security Gateways that use this Threat Prevention profile.

    • Protections to deactivate - The IPS protection categories in this section are NOT enabled on the Security Gateways that use this Threat Prevention profile.

    These categories only filter out or add protections that comply with the activation mode thresholds (Confidence, Severity, Performance).

    For example, if a protection is inactive because of its Performance rating, it is not enabled even if its category is in Protections to activate.

Updates

There are numerous protections available in IPS. It takes time to become familiar with those that are relevant to your environment. Some are easily configured for basic security and can be safely activated automatically.

In the Threat Prevention profile, you can configure an updates policy for IPS protections that were newly updated. You can do this with the IPS > Updates page in the Profiles navigation tree.

Best Practice - In the beginning, allow IPS to activate protections based on the IPS policy. During this time, you can analyze the alerts that IPS generates and how it handles network traffic, while you minimize the impact on the flow of traffic. Then you can manually change the protection settings to suit your needs.

Pre-R80 Settings

The Pre-R80 Settings are relevant for the pre-R80 gateways only.

Protections Activation

Excluded Protections Categories

Do not activate protections of the following categories - The IPS protection categories you select here are not automatically activated. They are excluded from the Threat Prevention policy ruleClosed Set of traffic parameters and other conditions in a Rule Base (Security Policy) that cause specified actions to be taken for a communication session. that has this profile in the action of the Rule BaseClosed All rules configured in a given Security Policy. Synonym: Rulebase..