The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Default settings

Prev Next

Once installed, Trellix Endpoint Security (ENS) for Mac starts protecting the Mac immediately with the default configurations defined. Review each settings and configure the protection features for your environment.

General

Feature

Default settings

Threat Prevention

Enabled

Firewall

Enabled

Web Control

Enabled

Depending upon the modules you selected during the installation, the features are displayed. For example, if you selected only Threat Prevention module, you can see only Threat Prevention in the General tab.

Threat Prevention

Feature

Default settings

Threat Prevention

On-access Scan tab settings:

  • Maximum scan time (in seconds) — 45 seconds for a file

  • Trellix GTI — Enable

  • Sensitivity level — Medium

  • Process Settings — Use Standard settings for all processes

Standard tab:

  • When to scan:

    • When writing to disk — Enabled

    • When reading from disk — Disabled

    • When reading/writing — Disabled

    • Let Trellix decide — Disabled

  • What to Scan:

    • On network drives — Disabled

    • Compressed archive files — Disabled

    • Compressed MIME-encoded files — Disabled

  • Additional scan options:

    • Detect unwanted programs — Enabled

    • Detect unknown program threats — Enabled

    • Detect unknown macro threats — Enabled

  • Actions:

    • Threat detection first response — Clean files

    • If first response fails — Delete files

    • Unwanted program first response — Clean files

    • If first response fails — Delete files

Threat Prevention

On-demand Scan tab settings:

Local ODS tab:

  • What to scan:

    • Archives & Compressed Files — Enabled

    • Apple Mail Messages — Enabled

    • Network Volumes — Disabled

  • Trellix GTI:

    • Enable Trellix GTI — Enabled

  • Sensitivity level — Medium

  • Actions:

    • Threat detection first response — Clean files

    • If first response fails — Delete files

    • Unwanted program first response — Clean files

    • If first response fails — Delete files

  • Scheduled Scan Options:

    • Scan only when the system is idle — Enabled

    • Scan anytime — Disabled

    • Do not scan when the system is on battery power — Enabled

Firewall

Feature

Default settings

Firewall

  • Regular Mode — Enabled

Trellix core networking rules

Trellix-Allow Bootp

Trellix-Allow DNS Resolution

  • Status — Enabled

  • Action — Allow

  • Direction — Either

  • Network Protocol — IP

    • Local IP(s) — Any

    • Remote IP(s) — Any

  • Transport Protocol — UDP

    • Local Port(s) — 68

    • Remote Port(s) — 67

  • Application — All

  • Logging — Disabled

  • Status — Enabled

  • Action — Allow

  • Direction — Outgoing

  • Network Protocol — IP

    • Local IP(s) — Any

    • Remote IP(s) — Any

  • Transport Protocol — UDP

    • Local Port(s) — Any

    • Remote Port(s) — 53

  • Application — All

  • Logging — Disabled



Trellix core networking rules contd..

Trellix-Allow Dat update http

Trellix-Allow Loopback

  • Status — Enabled

  • Action — Allow

  • Direction — Outgoing

  • Network Protocol — IP

    • Local IP(s) — Any

    • Remote IP(s) — update.nai.com

  • Transport Protocol — TCP

    • Local Port(s) — Any

    • Remote Port(s) — 80

  • Application — All

  • Logging — Disabled

  • Status — Enabled

  • Action — Allow

  • Direction — Either

  • Interface(s) — All

  • Network Protocol — IP

    • Local IP(s) — 127.0.0.1

    • Remote IP(s) — Any

  • Transport Protocol — Any

  • Application — All

  • Logging — Disabled



Additional Firewall core networking rules on systems managed by Trellix ePO - On-prem

Trellix-Allow ePO by Name

Trellix-Allow ePO by Address

Trellix-Allow Agent Wakeup

  • Status — Enabled

  • Action — Allow

  • Direction — Outgoing

  • Interface(s) — All

  • Network Protocol — IP

    • Local IP(s) — Any

    • Remote IP(s) — <ePO server name>

  • Transport Protocol — TCP

    • Local Port(s) — Any

    • Remote Port(s) — 443

  • Application — All

  • Logging — Disabled

  • Status — Enabled

  • Action — Allow

  • Direction — Outgoing

  • Interface(s) — All

  • Network Protocol — IP

    • Local IP(s) — Any

    • Remote IP(s) — <ePO server IP>

  • Transport Protocol — TCP

    • Local Port(s) — Any

    • Remote Port(s) — 443

  • Application — All

  • Logging — Disabled

  • Status — Enabled

  • Action — Allow

  • Direction — Incoming

  • Interface(s) — All

  • Network Protocol — IP

    • Local IP(s) — Any

    • Remote IP(s) — <ePO server IP>

  • Transport Protocol — TCP

    • Local Port(s) — 8081 (or port configured in ePO)

    • Remote Port(s) — Any

  • Application — All

  • Logging — Disabled



Default Client Rules

Block incoming pings

Allow all ICMP

Allow all high UDP

  • Status — Enabled

  • Action — Block

  • Direction — Incoming

  • Interface(s) — All

  • Network Protocol — IP

    • Local IP(s) — Any

    • Remote IP(s) — Any

  • Transport Protocol — ICMP

    • Message Type — Echo Request

  • Applications — All

  • Logging — Disabled

  • Status — Enabled

  • Action — Allow

  • Direction — Either

  • Interface(s) — All

  • Network Protocol — IP

    • Local IP(s) — Any

    • Remote IP(s) — Any

  • Transport Protocol — ICMP

    • Message Type — Any ICMP

  • Application — All

  • Logging — Disabled

  • Status — Enabled

  • Action — Allow

  • Direction — Either

  • Interface(s) — All

  • Network Protocol — IP

    • Local IP(s) — Any

    • Remote IP(s) — Any

  • Transport Protocol — UDP

    • Local Port(s) — (1024 - 65535)

    • Remote Port(s) — (1024 - 65535)

  • Application — All

  • Logging — Disabled



Default Client Rules contd..

Allow all outgoing traffic

Allow Loopback

  • Status — Enabled

  • Action — Allow

  • Direction — Outgoing

  • Interface(s) — All

  • Network Protocol — IP

    • Local IP(s) — Any

    • Remote IP(s) — Any

  • Transport Protocol — Any

  • Applications — All

  • Logging — Disabled

  • Status — Enabled

  • Action — Allow

  • Direction — Either

  • Interface(s) — All

  • Network Protocol — IP

    • Local IP(s) — 127.0.0.1

    • Remote IP(s) — Any

  • Transport Protocol — Any

  • Applications — All

  • Logging — Disabled



Web Control

Feature

Default settings

Web Control

  • Rating Actions for Sites

    • Red — Block

    • Yellow — Warn

    • Unrated — Allow

    • Unverified — Allow

  • Enable Web Category Blocking — Enabled

  • Block and Allow List — None

Update

Feature

Default settings

Update

In Schedule

  • Schedule — Daily at 4:45 PM (local time)

Logging

Feature

Default settings

Logging

In Enable Debug Logging

  • Threat Prevention — Disabled

  • Firewall — Disabled

  • Web Control — Disabled