The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Key features of Firewall

Prev Next

The key features of Firewall protect against threats, detect security issues, and correct false positives.

Protect

Protect your network and applications using these Firewall features:

  • Rules — Define the criteria Firewall uses to determine whether to block or allow incoming and outgoing traffic.

  • Rule groups — Organize firewall rules for easy management, enabling you to apply rules manually or on a schedule, and to only process traffic based on connection type.

  • Stateful packet filtering and inspection — Track network connection state and characteristics in a state table, allowing only packets that match a known open connection.

  • Reputation-based control — Block untrusted executables, or all traffic from an untrusted network, based on reputation.

Detect

Detect security issues using these Firewall features:

  • Dashboards and monitors — Display intrusion and detection events from Trellix GTI and Firewall.

  • Queries and reports — Retrieve detailed information about Firewall, including client rules, errors, intrusion and block events, and save that information in reports.

  • Alerts — Display alerts for blocked traffic, based on executable or network reputation.

  • Log traffic — Log all blocked or allowed traffic.

Correct

Reduce or eliminate false positives using these Firewall features:

  • Adaptive mode — Create rules automatically on the client system to allow legitimate activity.

    Once created, analyze client rules to decide which to convert to server-mandated policies.

  • Defined networks — Define trusted networks to allow traffic from networks that your organization considers safe.

  • Trusted executables — Maintain a list of safe executables to reduce false positives.

  • Firewall Catalog — Define rules and groups to add to multiple policies, or networks and applications to add to firewall rules.

  • Client options — Allow users to disable Firewall temporarily for troubleshooting.

  • Dashboards and monitors — Monitor activity and intrusion detections, then use that information to tune Firewall settings.