The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

How Trellix core networking rules work

Prev Next

Trellix core networking rules are provided by Trellix in the predefined Trellix core networking group and allow network traffic related to Trellix applications, DNS, and critical system processes.

You can't change or delete rules in this rule group. If you need to, you can create a duplicate of the group, make changes to the rules, then select the Disable Trellix core networking rules option in the Firewall Options policy to disable the group. But, this might disrupt network communications on the client system.

You might want to disable the Trellix core networking rules to have more control of network traffic using firewall rules. For example, allow DNS-related traffic to only specific DNS server IP addresses.

Best practice: If you disable Trellix core networking rules, make sure you thoroughly test the policy before implementing it in a production environment.

If you disable these rules, you might need to make configuration changes in the Firewall Options or Firewall Rules policy. The changes depend on what type of network traffic is blocked and how you want to allow the network traffic. For example, you can create specific firewall rules to allow traffic, or allow traffic by trusted executables or trusted networks.