Intrusion policy suppression configuration

Intrusion policy suppression configuration is a security mechanism that

  • suppresses intrusion event notification when a specific IP address or range of IP addresses triggers a specific rule or inspector,

  • eliminates false positives by allowing rules to trigger for all packets while only showing events for legitimate attacks, and

  • is useful for scenarios such as mail servers that transmit packets resembling specific exploits.

Mail server suppression example

If you have a mail server that transmits packets that look like a specific exploit, you might suppress event notification for that event when it is triggered by your mail server. The rule triggers for all packets, but you only see events for legitimate attacks.