The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Create a firewall rule group

Prev Next

Create rule groups and add related rules to the group for better management.

For details about product features, usage, and best practices, click ? or Help.

  1. Log on to the ePO - On-prem server as an administrator.

  2. From the Policy Catalog, select Endpoint Security Firewall as the product, then select Rules as the category.

  3. Click Add Group to create a Firewall group, define these settings, then click Save.

    In this category...

    In this section...

    Configure these options...

    Description

    Name

    Type a name of the group.

    Status

    Select Enable group to enable the rule group on managed Mac.

    Direction

    • Either — Matches incoming and outgoing traffic.

    • In — Matches incoming traffic.

    • Out — Matches outgoing traffic.

    Notes

    You can store additional information.

    Location awareness

    Enable location awareness

    Enable or disable location information of the group. For more information, see Configure location awareness options.

    Require the ePolicy Orchestrator be reachable

    Enables the group to match only if there is communication with the ePO - On-prem server and the FQDN of the server is resolved.

    Location criteria

    Define criteria for Firewall to identify network location.

    Networks

    Network Protocol

    • Any protocol — Supports only IPv4 protocol.

    • IP protocol — Supports only IPv4 protocol.

    Connection types

    • Wired

    • Wireless

    • Virtual

    Specify networks

    • Add Local — Adds local networks.

    • Add Remote — Adds remote networks.

    • Add from Catalog (Local) — Adds local networks from the catalog.

    • Add from Catalog (Remote) — Adds remote networks from the catalog.

    Transport

    Transport protocol

    • ICMP — Matches ICMP protocol.

    • TCP — Matches TCP protocol.

    • UDP — Matches UDP protocol.

    • All protocol — Matches ICMP, TCP, or UDP protocol.

  4. Verify the configuration details, then click Save.