The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

FAQ — Adaptive mode

Prev Next

Here are answers to frequently asked questions.

Adaptive mode is a setting that you can apply to Firewall when testing new rollouts. This mode enables the client system to automatically create rules that allow activity while preserving minimum protection against vulnerabilities. The following questions and answers can help you use this feature.

How do you turn on Adaptive mode?

Enable this option in the Host Intrusion Prevention Options policy and apply this policy to the client.

How does Adaptive mode work with Host Intrusion Prevention?

Adaptive mode creates client-side rules that allow network packets not covered by existing firewall rules. Firewall client rules are created on a per-process basis. The processes associated with firewall client rules are based on path, file description, digital signature, and MD5 hash.

When is a rule not created automatically with Adaptive mode?
  • There is already a rule in the applied Rules policy that blocks or allows the packet.

  • The packet isn't TCP, UDP, or ICMP.