The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure location awareness options

Prev Next

A location awareness policy enables administrators to enforce rules based on the network to which the Mac is connected.

A location awareness policy contains a set of defined rules. When a network packet matches certain criteria with the group definitions, such as ePO reachability or DNS server address, the group becomes active. When the location awareness group is active, the rules in the group are also considered for matching.

  1. Log on to the ePO - On-prem server as an administrator.

  2. From the Policy Catalog, select Endpoint Security Firewall as the product, then select Rules as the category.

  3. Click the policy that you want to configure location awareness settings. .

    Note

    To create a new policy, click New Policy, type a name for the policy, then click OK to open the policy page.

  4. Click Add Group to add a group.

  5. Type a name for the Group, select Enable group, then select Direction options.

  6. Select Enable Location Awareness.

  7. On the Location section, define these parameters, then click Next.

    • Name — Type a name for the policy.

    • Require that ePolicy Orchestrator be reachable — Enable the group to match only if there is communication with the Trellix ePO - On-prem server and the FQDN of the server is resolved.

    • Location criteria

      • Connection-specific DNS suffix — Specify a connection-specific DNS suffix in the format: domain.com.

      • Default gateway — Specify a single IP address for a default gateway in IPv4 format.

      • DHCP server — Specify a single IP address for a DHCP server in IPv4 format.

      • DNS server — Specify a single IP address for a domain name server in IPv4 format.

      • Primary WINS — Specify a single IP address for a primary WINS server in IPv4 format.

      • Secondary WINS — Specify a single IP address for a secondary WINS server in IPv4 format.

      • Domain reachability (HTTPS) — Specify a domain name.

    You can use the Add from Catalog option to add settings from the catalog.