You can configure firewall rules to block or allow traffic, specify networks and executables, and optionally display alerts. Groups can be location-aware. Both rules and groups can be enabled and disabled on a schedule.
| Section | Option | Definition | Rule | Group |
|---|---|---|---|---|
| Description | Name | Specifies the descriptive name of the item (required). |
|
|
| Status | Enables or disables the item. |
|
|
|
| Specify actions | Allow — Allows traffic through the firewall if the item is matched. |
|
||
| Block — Stops traffic from passing through the firewall if the item is matched. |
|
|||
| Treat match as intrusion — Treats traffic that matches the rule as an
intrusion and displays an alert.
Best practice: Don't enable this option for an Allow rule because it generates many alerts. |
||||
| Log matching traffic — Treats traffic that matches the rule as a detection and displays an event in the Event Log on the Endpoint Security Client. |
|
|||
| Direction | Specifies the direction:
|
|
|
|
| Notes | Provides more information about the item. |
|
|
|
| Location | Enable location awareness | Enables or disables location information for the group. |
|
|
| Name | Specifies the name of the location (required). |
|
||
| Enable connection isolation | Blocks traffic on network adapters that don't match the group when an adapter is present that does match the group.
One use of this option is to block traffic generated by potentially undesirable sources outside the corporate network from entering the corporate network. Blocking traffic in this way is possible only if a rule preceding the group in the firewall hasn't already allowed it. When connection isolation is enabled and a NIC matches the group, the group allows traffic only when one of the following applies:
If no NIC matches the group, the group is ignored and rule matching continues. |
|
||
| Location criteria |
Example formats:
|
|
||
| Networks | Specifies the network host options that apply to the item. |
|
|
|
| Network protocol | Specifies the network protocol that applies to the item. |
|
|
|
| Any protocol | Allows both IP and non-IP protocols.
If a transport protocol or an application is specified, only IP protocols are allowed. |
|
|
|
| IP protocol | Excludes non-IP protocols.
If neither checkbox is selected, any IP protocol applies. Both IPv4 and IPv6 can be selected for Windows systems. |
|
|
|
| Non-IP protocol | Includes non-IP protocols only.
|
|
|
|
| Connection types | Indicates if one or all connection types apply:
|
|
|
|
| Specify networks | Specifies the networks that apply to the item.
|
|
|
|
| Transport | Specifies transport options that apply to the item. | |||
| Transport protocol | Specifies the transport protocol associated with the item.
Select the protocol, then click Add to add ports.
|
|
|
|
| Executables |
Specifies the executables that apply to the rule.
|
|
|
|
| Schedule | Specifies schedule settings for the rule or group. |
|
|
|
| Enable schedule | Enables the schedule for the timed rule or group.
When the schedule is disabled, the rule or rules in the group, don't apply.
For start and end times, use a 24-hour clock style. For example, 13:00 = 1 p.m. You can either schedule Firewall timed groups or allow the user to enable them from the Trellix system tray icon. |
|
|
|
| Disable schedule and enable the group from the Trellix system tray icon | Specifies that the user can enable the timed group for a set number of minutes from the
Trellix notification area icon instead of using the schedule.
Best practice: Use this option to allow broad network access, for example at a hotel, before a VPN connection can be established. Selecting this option displays more menu options under Quick Settings in the Trellix notification area icon:
|
|
||
| Number of minutes (1-60) to enable the group | Specifies the number of minutes (1–60) that the timed group is enabled after selecting Enable Firewall Timed Groups from the Trellix notification area icon. |
|