The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Firewall rules in the Trellix core networking group

Prev Next

The Trellix core networking group includes firewall rules to allow network traffic related to Trellix applications, DNS, and critical system processes.

Note

If you select the Disable Trellix core networking rules option in the Firewall Options policy, Firewall only disables some of the rules. This prevents Firewall from blocking specific types of critical application and non-application network traffic that could cause outages.

Firewall rule

Description

Can you disable it?

Allow outbound system applications

Allows outbound network traffic for the Windows SYSTEM executable process.

Yes

Allow ARP traffic

Allows inbound and outbound network traffic for ARP (Address Resolution Protocol) packets (Ethernet Protocol 0x806).

No

Allow EAPOL traffic

Allows inbound and outbound network traffic for EAPOL (Extensible Authentication Protocol over LAN) packets (Ethernet Protocol 0x888E).

Yes

Allow outbound stock applications

Allows outbound network traffic for Windows critical processes. For example, services.exe, svchost.exe, lsass.exe, userinit.exe, winlogon.exe, alg.exe, spoolsv.exe, and dns.exe.

Yes

Allow McAfee signed applications

Allows inbound and outbound network traffic related to Trellix products based on signer certificate value.

No

Allow outbound ICMPv4 traffic

Allows outbound network traffic related to the ICMPv4 transport protocol.

Yes

Allow outbound ICMPv6 traffic

Allows outbound network traffic related to the ICMPv6 transport protocol.

Yes

Allow outbound DNS traffic

Allows outbound network traffic related to remote host UDP Port 53 (default port for DNS resolution).

Yes

Allow inbound traffic from special IP addresses

Allows inbound network traffic for the special IP address 0.0.0.0 (IPv4 and IPv6).

Yes

Allow outbound loopback and broadcast traffic

Allows outbound network traffic related to IPv4/IPv6 loopback and broadcast traffic.

Yes

Allow reserved IP traffic

Allows inbound and outbound network traffic for the RESERVED Transport Protocol 255 (0xFF).

Yes

Allow outbound BOOTP traffic

Allows outbound network traffic for BOOTP and DHCP traffic (UDP port 67 and 68).

No

Allow outbound DHCPv6 traffic

Allows outbound network traffic for DHCPv6 traffic (UDP port 546 and 547).

Yes