Skip to content

Security Intrusion Prevention Profile

Configure Security Intrusion Prevention Profile.

Diagram

policy_object_profile (sdwan.feature_profiles)

Section titled “policy_object_profile (sdwan.feature_profiles)”
NameTypeConstraintMandatoryDefault Value
security_intrusion_prevention_profilesList[security_intrusion_prevention_profiles]No

security_intrusion_prevention_profiles (sdwan.feature_profiles.policy_object_profile)

Section titled “security_intrusion_prevention_profiles (sdwan.feature_profiles.policy_object_profile)”
NameTypeConstraintMandatoryDefault Value
nameStringRegex: ^[^&<>! "]{1,32}$Yes
alert_log_levelChoiceemergency, alert, critical, error, warning, notice, info, debugNoerror
custom_signature_setBooleantrue, falseNofalse
inspection_modeChoicedetection, protectionYes
signature_allow_listStringRegex: ^[^&<>! "]{1,32}$No
signature_setChoicebalanced, connectivity, securityYes

Example-1: This example demonstrates how to configure a Security Intrusion Prevention Profile with alert_log_level, custom_signature_set, inspection_mode, signature_allow_list, and signature_set.

sdwan:
feature_profiles:
policy_object_profile:
security_intrusion_prevention_profiles:
- name: intrusion_prevention_full
alert_log_level: critical
custom_signature_set: false
inspection_mode: detection
signature_allow_list: security_ips_signature
signature_set: balanced