You can enable and disable the Firewall module, configure protection options, and define networks and trusted executables to use in rules and groups.
To reset the settings to the Trellix default settings and cancel your changes, click Reset to Default.
Note
Host Intrusion Prevention 8.0 can be installed on the same system as Trellix ENS version 10.7. If McAfee Host IPS Firewall is installed and enabled, Firewall is disabled even if enabled in the settings.
| Section | Option | Definition |
|---|---|---|
| Enable Firewall | Enables and disables the
Firewall module.
(Enabled by default) |
|
| Protection Options | Allow traffic for unsupported protocols | Allows all traffic that uses unsupported protocols. When disabled, all traffic using unsupported protocols is blocked.
(Disabled by default) |
| Allow only outgoing traffic until firewall services have started |
Allows outgoing traffic but no incoming traffic until the
Firewall service starts.
|
|
| Allow bridged traffic | Allows:
(Disabled by default) |
|
| Enable firewall intrusion alerts | Displays alerts automatically when
Firewall detects a potential attack.
(Enabled by default) |
|
| DNS Blocking | Domain name | Defines domain names to block.
When applied, this setting adds a rule near the top of the firewall rules that blocks connections to the IP addresses resolving to the domain names.
|
| Section | Option | Definition |
|---|---|---|
| Tuning Options | Enable Adaptive mode | Creates rules automatically to allow traffic.
(Disabled by default) Best practice: Enable Adaptive mode temporarily on a few systems only while tuning Firewall. |
| Disable Trellix core networking rules | Disables the built-in
Trellix networking rules (in the
Trellix core networking rule group).
(Disabled by default) If you select this option, Firewall only disables some of the rules. This prevents Firewall from blocking specific types of critical application and non-application network traffic that could cause outages.
|
|
| Log all blocked traffic (Windows only) | Logs all blocked traffic to the
Firewall event log (FirewallEventMonitor.log) on the client system.
(Enabled by default) |
|
| Log all allowed traffic (Windows only) | Logs all allowed traffic to the
Firewall event log (FirewallEventMonitor.log) on the client system.
(Disabled by default)
|
|
| Trellix GTI Network Reputation | Treat Trellix GTI match as intrusion | Treats traffic that matches the
Trellix GTI
block threshold setting as an
intrusion and displays an alert.
Any IP address for a trusted network is excluded from Trellix GTI lookup. (Disabled by default)If GTI IP reputation is enabled, we recommend you enable Treat Trellix GTI match as intrusion. |
| Log matching traffic | Treats traffic that matches the
Trellix GTI
block threshold setting as a
detection and displays an event in the
Event Log on the
Endpoint Security Client.
(Disabled by default) If GTI IP reputation is enabled, we recommend you enable Log matching traffic. Any IP address for a trusted network is excluded from Trellix GTI lookup. |
|
| Block all untrusted executables | Blocks network activity from all executables that are not signed, have invalid signatures, or have unknown reputations (Disabled by default).
Best practice: To allow a trusted unsigned executable, add it to Trusted Executables list. |
|
|
Incoming network-reputation threshold
Outgoing network-reputation threshold |
Specifies the
Trellix GTI
rating threshold for blocking incoming or outgoing traffic from a network connection.
|
|
| If Trellix GTI ratings server is not reachable | Specifies whether to block or allow traffic by default if
Trellix GTI
is not available:
|
|
| Stateful Firewall | Use FTP protocol inspection | Allows FTP connections to be tracked so that they require only one firewall rule for outgoing FTP client traffic and incoming FTP server traffic.
If not selected, FTP connections require a separate rule for incoming FTP client traffic and outgoing FTP server traffic. (Enabled by default) |
| Number of seconds (1-240) before TCP connections time out | Specifies the time, in seconds, that an unestablished TCP connection remains active if no more packets matching the connection are sent or received. The valid range is 1–240. | |
| Number of seconds (1-300) before UDP and ICMP echo virtual connections time out | Specifies the number of seconds that a UDP or ICMP Echo virtual connection remains active if it receives or sends no more packets that match the connection. This option resets to its configured value every time a packet that matches the virtual connection is sent or received. The valid range is 1–300. | |
| Defined Networks | Defines network addresses, subnets, or ranges to use in rules and groups or defines networks as
trusted.
|
|
| Address type | Specifies the address type of the network to define. | |
| Trusted |
|
|
| Owner | ||
| Trusted Executables | Specifies executables that are safe in any environment and have no known vulnerabilities. These executables are allowed to perform all operations except operations that suggest that the executables have been compromised.
Configuring a trusted executable creates a bi-directional Allow rule for that executable at the top of the Firewall rules list.
|