Use block lists to block specific traffic from all network devices that support blocking.
You must be a super user to use the block list function.
Configure global block lists:
On the system navigation tree, select System Properties, then click Global Block List.
Select the Blocked Sources, Blocked Destinations, or Exclusions tab, then manage block list entries.
For Exclusions, manage the list of IP addresses that should never be blocked automatically, such as DNS and other servers, or the system administrator's workstation.
Default is zero (0), which allows any port. Type a port number if you want to narrow the effect of the block list to a specific destination port.
Select the network devices that support the global block list.
Add block list entries for Trellix Intrusion Prevention System Manager through the sensors:
On the system navigation tree, select NSM Properties, click Block List, then select a sensor.
To apply the global block list entries to this sensor, select Include Global Block List. If duplicate IP addresses exist, the global block list address overwrites the Trellix Intrusion Prevention System Manager address.
Note
Once you select this option, you can only delete items manually. The entry appears on the block list until its duration expires.
Manage removed block list entries for Trellix Intrusion Prevention System Manager.
Entries initiated on Trellix ESM that have not yet expired but that do not return block list entries when you query Trellix Intrusion Prevention System Manager, display with a Removed status and a flag icon. This condition occurs if you remove the entry, but do not initiate the removal on Trellix ESM. You can add this entry to or delete it from the block list.
On the system navigation tree, select NSM Properties, then click Block List.
Select the removed entry on the list of block list entries, then click Add or Delete.
Click Apply or OK.