The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Manage Firewall client rules

Prev Next

Tune and tighten security by reviewing Firewall client rules and moving them to a Rules policy.

Firewall client rules are created manually on a client or automatically in Adaptive mode.

For information about server tasks, see the ePO - On-prem documentation.

  1. From the System Tree, click Wake Up Agents.

    The agent wake-up call collects the Firewall client properties, including client rules, from the client.

  2. The Endpoint Security Firewall Property Translator task runs automatically every 15 minutes, scans the client properties for Firewall client rules, and adds them to the Firewall Client Rules page.

    Important

    Make sure in the ePO - On-prem server that the Endpoint Security Firewall Property Translator server task is left in a Disabled state. Enabling this task would run it in addition to the automatic execution mentioned above which may cause performance issues.

    You can also manually run the client rule conversion as needed:

    Select MenuAutomationServer Tasks, then run the Endpoint Security Firewall Property Translator server task.

  3. Select MenuReportingFirewall Client Rules.

  4. In the System Tree, select a group to display its details.

  5. Review the client rules to determine which rules to promote to a Rules policy.

  6. Move rules to a policy by selecting rules, clicking New Firewall Rule, then indicating the policy to move the rules to.

  7. In the Firewall Options policy, deselect these options:

    • Enable Adaptive mode

    • Retain existing user-added rules and Adaptive mode rules when this policy is enforced

  8. Enforce the updated Options and Rules policies.

The rules from the Rules policy replace the client rules that were created on the client system.