Users with the tenant administrator role or a custom role with appropriate IPS tasks can edit, clone, or delete IPS signature dynamic groups.
You can edit only customized IPS signature dynamic groups and not predefined (system-generated) dynamic groups.
To edit a customized IPS signature dynamic group:
The IPS Signatures page appears.
The Edit IPS Signature Dynamic Group page appears, displaying the same fields that are presented when you create an IPS signature dynamic group.
Note You can modify all fields except the name.
The IPS Signatures page appears displaying the list of IPS signatures matching the filters. If the signatures do not match, you can tweak the filter criteria as needed. Click Close to go back to the previous page.
You are returned to the IPS Signatures page and a message indicating that the IPS signature dynamic group was successfully updated is displayed.
If the IPS signature dynamic group was used in an IPS or exempt rule that is deployed on the device (through the firewall policy), then the firewall policy is marked for deployment. You must deploy the firewall policy for the changes to take effect on the device.
Cloning enables you to easily create a new IPS signature dynamic group based on an existing one. You can clone predefined or customized IPS signature dynamic groups and modify the parameters as needed.
To clone an IPS signature dynamic group:
The IPS Signatures page appears.
The Clone IPS Signature Dynamic Group page appears, displaying the same fields that are presented when you create an IPS signature dynamic group.
The IPS Signatures page appears displaying the list of IPS signatures matching the filters. If the signatures do not match, you can tweak the filter criteria as needed. Click Close to go back to the previous page.
You are returned to the IPS Signatures page and a message that the IPS signature dynamic group was successfully created is displayed.
After you clone an IPS signature dynamic group, you can use the dynamic group in an IPS or an exempt rule and reference the IPS profile (containing the rule) in a firewall policy that you can then deploy on the device.
Note
You can delete only customized (user-created) IPS signature dynamic groups that are not used in an IPS or exempt rule.
You cannot delete predefined (system-generated) IPS signature dynamic groups.
To delete one or more customized IPS signature dynamic groups:
The IPS Signatures page appears.
A warning message appears asking you to confirm the deletion.
You are returned to the IPS Signatures page and a message indicating the status of the delete operation is displayed.