The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Create a Firewall rule

Prev Next

Create firewall rules to handle the network traffic according to your requirements.

  1. Click the Trellix menulet GUID-9BE2692D-7F54-44CB-AE3B-3D141955024E-low.png on the status bar, then select Preferences.

  2. Click Firewall.

  3. Click GUID-8CC2C84C-B44D-4B10-A920-D4E503DB9CC1-low.png, type the administrator password, then click OK.

  4. Select Regular Mode.

  5. Click GUID-213AEF71-3D9B-4242-AB47-3B513C7B845E-low.gif in the bottom left corner of the console to open the rule page.

    GUID-ECBA1750-5D2A-44AC-84B7-596AE74E66E3-low.png
  6. Define the following parameters as needed, then click OK.

    For this field...

    Configure these options...

    Rule Name

    Type a name for the rule.

    Status

    • Enabled — To enable the firewall rule.

    • Disabled — To disable the firewall rule.

    Note

    The rules appear as grayed out in the rules list, when their status is set to Disabled.

    Action

    • Block — To block the network traffic.

    • Allow — To allow the network traffic.

    Direction

    • Incoming — To apply the rules for incoming network traffic.

    • Outgoing — To apply the rules for outgoing network traffic.

    Logging

    • Enabled — To make an entry in the system log, when a network packet matches a rule.

    • Disabled — To avoid making an entry in the system log when the network packet matches a rule.

    Caution

    Enabling the logging feature can impact the system performance. We recommend that you enable Logging only for troubleshooting and learning purpose.

    Interface(s)

    • Wired

    • Wireless

    • Virtual

    Network Protocol IPv4

    Define the configuration for Local Mac using:

    • Single

    • Subnet

    • Local Subnet

    • Range (of IP addresses)

    • Fully Qualified Domain Name

    • Any local IP Address

    • Any IPv4 Address

    Tip

    Local system is the system on which you are adding rules.

    Select the configuration for Remote system using:

    • Single

    • Subnet

    • Local Subnet

    • Range (of IP addresses)

    • Fully Qualified Domain Name

    • Any local IP Address

    • Any IPv4 Address

    Tip

    Remote system is the system you want to connect.

    Note

    Use to add more criteria and to remove existing criteria.

    Transport Protocol

    Select All Protocols to apply the rule for all protocols.

    For Select Protocol, define the parameters for:

    • TCP

    • UDP

    • ICMP

    Note

    Use to add more criteria and to remove existing criteria.

    Tip

    Add specific rules at the top of the list, and generic rules at the bottom to filter the traffic most efficiently.

  7. Click to prevent further changes.

    Note

    To edit an existing Firewall rule, select the rule, then click to open the rule page.