Define rules for specific endpoints

Prev Next

If you are a   Trellix ePO - On-prem administrator, you can add prepopulated rules to allow or ban an application or executable file for specific endpoints in your administered groups. Or, you can define custom rules for specific endpoints or groups, as needed.  

Task

  1. On the   Trellix ePO - On-prem console, select   MenuApplication ControlPolicy Discovery to open the   Policy Discovery page.    

  2. Select the request where you want to define custom rules.    

  3. Click   ActionsCreate Custom Policy to open the   Policy Discovery: Custom Rules page.    

  4. You can review rules or define custom rules:    

    • Review or add rules — Select   Approve Request,   Ban Request, or   Allow Trusted Path, then review or add more rules as needed.  

    • Define custom rules — Select   Clear and define Rules, then review the request details and define relevant rules as needed.  

  5. Specify the rule group for the rules.    

    • To add the rules to an existing rule group, select   Choose existing and select the rule group from the list.  

      Note

      When adding rules to allow a network path, select your rule group carefully. If you add rules to the   Global Rules rule group, all future requests received from that network path are automatically approved. Or, if you add your rules to a custom rule group, future requests from that network path aren't automatically approved.  

    • To create a rule group with the rules, select   Create new and enter the rule group name.  

  6. (Optional) Add the changed or created rule group to a policy.    

    1. Select   Add rule group to existing policy.    

    2. Select the policy where you want to add the rule group.    

  7. Click   Save.    

    This approves all grouped requests. For requests received from network paths, when you click   Save, the   Approve Requests for Subdirectories pop-up window appears that includes a checkbox to approve all related requests. If needed, select the checkbox, then click   OK to approve all requests received from the network path and its subdirectories.