The Trellix core networking group includes firewall rules to allow network traffic related to Trellix applications, DNS, and critical system processes.
Note
If you select the Disable Trellix core networking rules option in the Firewall Options policy, Firewall only disables some of the rules. This prevents Firewall from blocking specific types of critical application and non-application network traffic that could cause outages.
Firewall rule | Description | Can you disable it? |
|---|---|---|
Allow outbound system applications | Allows outbound network traffic for the Windows SYSTEM executable process. | Yes |
Allow ARP traffic | Allows inbound and outbound network traffic for ARP (Address Resolution Protocol) packets (Ethernet Protocol 0x806). | No |
Allow EAPOL traffic | Allows inbound and outbound network traffic for EAPOL (Extensible Authentication Protocol over LAN) packets (Ethernet Protocol 0x888E). | Yes |
Allow outbound stock applications | Allows outbound network traffic for Windows critical processes. For example, services.exe, svchost.exe, lsass.exe, userinit.exe, winlogon.exe, alg.exe, spoolsv.exe, and dns.exe. | Yes |
Allow McAfee signed applications | Allows inbound and outbound network traffic related to Trellix products based on signer certificate value. | No |
Allow outbound ICMPv4 traffic | Allows outbound network traffic related to the ICMPv4 transport protocol. | Yes |
Allow outbound ICMPv6 traffic | Allows outbound network traffic related to the ICMPv6 transport protocol. | Yes |
Allow outbound DNS traffic | Allows outbound network traffic related to remote host UDP Port 53 (default port for DNS resolution). | Yes |
Allow inbound traffic from special IP addresses | Allows inbound network traffic for the special IP address 0.0.0.0 (IPv4 and IPv6). | Yes |
Allow outbound loopback and broadcast traffic | Allows outbound network traffic related to IPv4/IPv6 loopback and broadcast traffic. | Yes |
Allow reserved IP traffic | Allows inbound and outbound network traffic for the RESERVED Transport Protocol 255 (0xFF). | Yes |
Allow outbound BOOTP traffic | Allows outbound network traffic for BOOTP and DHCP traffic (UDP port 67 and 68). | No |
Allow outbound DHCPv6 traffic | Allows outbound network traffic for DHCPv6 traffic (UDP port 546 and 547). | Yes |