The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

How firewall rules are organized

Prev Next

Rules are categorized as ePO Rules, Client Rules, and Adaptive Rules.

Rules are displayed in tree view. The ePO Rules group appears at the top with the list of rules, followed by Client Rules, then Adaptive Rules.

Tip

To view firewall rules, click GUID-9BE2692D-7F54-44CB-AE3B-3D141955024E-low.png | Preferences | Firewall.

  • ePO Rules — Defined and enforced by administrators if your Mac is managed by ePO - On-prem.

    The ePO Rules group also contains list of rules that firewall creates automatically at run time for business continuity. These rules can't be modified.

    • ePO Rules are displayed and applied only when the Mac is managed by ePO - On-prem.

    • A local user can't modify ePO Rules.

    • A user can't add rules above or in between ePO Rules.

    • When rules are created from a client Mac, they are added after the existing rules in the Client Rules section.

    • ePO Rules are the first rules processed to match the network packet.

    • These rules allow the Mac to:

      • Obtain an IP address using DHCP.

      • Perform DNS queries.

      • Perform DAT updates.

      • Allow communication with ePO - On-prem.

  • Client Rules — Created locally to allow or block specific network access.

  • Adaptive Rules — Created automatically, when Firewall is running in Adaptive mode to allow a non-matching network packet.