The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in mid-October 2026. We hope you enjoy the updated experience.

Making groups location-aware

Prev Next

You can make a group and its rules location-aware and create connection isolation.

Note

Settings for Transport and Executables aren't available for connection isolation groups.

The Location and Network Options of the group enable you to make the groups network adapter-aware. Use network adapter groups to apply adapter-specific rules for computers with multiple network interfaces. After enabling location status and naming the location, parameters for allowed connections can include the following for each network adapter:

  • Location:

    • Connection-specific DNS suffix

    • Default gateway IP address

    • DHCP server IP address

    • DNS server queried to resolve URLs

    • Primary WINS server IP address

    • Secondary WINS server IP address

    • Domain reachability (HTTPS)

    • Registry key

    Note

    If you specify more than one location-criteria parameter, all are applied to the location-aware group.

  • Networks (local):

    • Single IP address

    • Range

    • Subnet

If two location-aware groups apply to a connection, Firewall uses normal precedence, processing the first applicable group in its rule list. If no rule in the first group matches, rule processing continues.

When Firewall matches a location-aware group’s parameters to an active connection, it applies the rules in the group. It treats the rules as a small rule set and uses normal precedence. If some rules don't match the intercepted traffic, Firewall ignores them.

If this option is selected...

Then...

Enable location awareness

A location name is needed.

Require that ePO - On-prem is reachable

The ePO - On-prem is reachable and the FQDN of the server has been resolved.

To determine whether the ePO - On-prem server is available, Firewall performs DNS and WINS queries for the ePO - On-prem server name, which is registered with Trellix Agent. If both WINS and DNS fail to resolve the name, the ePO - On-prem server is not available.

Local Network

The IP address of the adapter must match one of the list entries.

Connection-specific DNS suffix

The DNS suffix of the adapter must match one of the list entries.

Default gateway

The default adapter gateway IP address must match at least one of the list entries.

DHCP server

The adapter DHCP server IP address must match at least one of the list entries.

DNS server

The adapter DNS server IP address must match any of the list entries.

Primary WINS server

The adapter primary WINS server IP address must match at least one of the list entries.

Secondary WINS server

The adapter secondary WINS server IP address must match at least one of the list entries.

Domain reachability (HTTPS)

The specified domain must be reachable using HTTPS.

To determine whether the domain is reachable, Firewall checks for the valid SSL certificate of the domain. The location-aware group criteria matches and the rules are applied only if the domain has a valid certificate.

Registry Key

The value given in the registry key criteria must match the windows registry key.

You can select a criteria from the above list, or you can choose not to provide any criteria, which would mean that the Location Aware Group is always enabled.

Location Criteria of similar type is OR with each other, and criteria of different type is AND with each other. See below:

Location Aware Groups

Connection-specific DNS suffix

OR

Connection-specific DNS suffix

AND

Default gateway

OR

Default gateway

AND

DHCP server

OR

DHCP server

AND

DNS server

OR

DNS server

AND

Primary WINS server

OR

Primary WINS server

AND

Secondary WINS server

OR

Secondary WINS server

AND

Domain reachability (HTTPS)

OR

Domain reachability (HTTPS)

AND

Registry Key

OR

Registry Key