The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Create timed groups on a client system

Prev Next

You can create Firewall timed groups to restrict Internet access until a client system connects over a VPN.

Before you begin

Make sure that the interface mode for the Trellix Endpoint Security (ENS) Client is set to Full access or log on to the Trellix Endpoint Security (ENS) Client as administrator.



Task
  1. Open the Trellix Endpoint Security (ENS) Client.

  2. Click Firewall on the main Status page.

    Or, from the Action menu GUID-A3B12F55-7EE9-4519-8FCA-9ACA85C3661F-low.png, select Settings, then click Firewall on the Settings page.

  3. Create a Firewall group with default settings that allow Internet connectivity. For example, allow port 80 HTTP traffic.

  4. In the Schedule section, select how to enable the group.

    • Enable schedule — Specifies a start and end time for the group to be enabled.

    • Disable schedule and enable the group from the Trellix system tray icon — Allows users to enable the group from the Trellix system tray icon and keeps the group enabled for the specified number of minutes.

      If you allow users to manage the timed group, you can optionally require that they provide a justification before enabling the group.

  5. Click OK to save your changes.

  6. Create a connection isolation group that matches the VPN network to allow needed traffic.

    Tip

    Best practice: To allow outbound traffic from only the connection isolation group on the client system, don't place any Firewall rules below this group.

  7. Click Apply.