The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Create timed groups

Prev Next

You can create Firewall timed groups to restrict Internet access until a client system connects over a VPN.

To enable this feature, complete the following steps:

  1. Select Menu.

  2. Select Policy.

  3. Select Policy Catalog.

  4. Select Endpoint Security Firewall from the product list.

  5. Select the Rules policy.

  6. Select an editable policy.

  7. Create or edit a Firewall group with your rule configuration settings that allows Internet connectivity. For example, allow port 80 HTTP or 443 HTTPS traffic.

  8. From the Schedule section, select how to enable the group:

    • Enable Schedule: Use this feature to schedule when the group is enabled

      Important

      Do not enable this option to convert the Firewall Group to a time-based group.

    • Disable schedule and enable the group from the Trellix system tray icon: Use this feature to enable the group for a specified timeframe.

      Note

      You can specify that Users justify their use of the time-based firewall group function before enabling the group. To enable this feature, select the "Require justification from users when managing Firewall from the Trellix system tray icon" setting within the Firewall Options policy.

  9. Create a connection isolation group that matches the VPN network to allow needed traffic.

    Tip

    To allow outbound traffic from only the connection isolation group on the client system, don't place any Firewall rules below this group.

  10. Click Save.