You can make a group and its rules location-aware and create connection isolation.
Note
Settings for Transport and Executables aren't available for connection isolation groups.
The Location and Network Options of the group enable you to make the groups network adapter-aware. Use network adapter groups to apply adapter-specific rules for computers with multiple network interfaces. After enabling location status and naming the location, parameters for allowed connections can include the following for each network adapter:
Location:
Connection-specific DNS suffix
Default gateway IP address
DHCP server IP address
DNS server queried to resolve URLs
Primary WINS server IP address
Secondary WINS server IP address
Domain reachability (HTTPS)
Registry key
Note
If you specify more than one location-criteria parameter, all are applied to the location-aware group.
Networks (local):
Single IP address
Range
Subnet
If two location-aware groups apply to a connection, Firewall uses normal precedence, processing the first applicable group in its rule list. If no rule in the first group matches, rule processing continues.
When Firewall matches a location-aware group’s parameters to an active connection, it applies the rules in the group. It treats the rules as a small rule set and uses normal precedence. If some rules don't match the intercepted traffic, Firewall ignores them.
If this option is selected... | Then... |
|---|---|
Enable location awareness | A location name is needed. |
Require that Trellix ePO - On-prem is reachable | The Trellix ePO - On-prem is reachable and the FQDN of the server has been resolved. To determine whether the Trellix ePO - On-prem server is available, Firewall performs DNS and WINS queries for the Trellix ePO - On-prem server name, which is registered with Trellix Agent. If both WINS and DNS fail to resolve the name, the Trellix ePO - On-prem server is not available. |
Local Network | The IP address of the adapter must match one of the list entries. |
Connection-specific DNS suffix | The DNS suffix of the adapter must match one of the list entries. |
Default gateway | The default adapter gateway IP address must match at least one of the list entries. |
DHCP server | The adapter DHCP server IP address must match at least one of the list entries. |
DNS server | The adapter DNS server IP address must match any of the list entries. |
Primary WINS server | The adapter primary WINS server IP address must match at least one of the list entries. |
Secondary WINS server | The adapter secondary WINS server IP address must match at least one of the list entries. |
Domain reachability (HTTPS) | The specified domain must be reachable using HTTPS. To determine whether the domain is reachable, Firewall checks for the valid SSL certificate of the domain. The location-aware group criteria matches and the rules are applied only if the domain has a valid certificate. |
Registry Key | The value given in the registry key criteria must match the windows registry key. |
You can select a criteria from the above list, or you can choose not to provide any criteria, which would mean that the Location Aware Group is always enabled.
Location Criteria of similar type is OR with each other, and criteria of different type is AND with each other. See below:
Location Aware Groups |
|---|
Connection-specific DNS suffix OR Connection-specific DNS suffix |
AND |
Default gateway OR Default gateway |
AND |
DHCP server OR DHCP server |
AND |
DNS server OR DNS server |
AND |
Primary WINS server OR Primary WINS server |
AND |
Secondary WINS server OR Secondary WINS server |
AND |
Domain reachability (HTTPS) OR Domain reachability (HTTPS) |
AND |
Registry Key OR Registry Key |