The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Predefined firewall rule groups in ePO - On-prem

Prev Next

The predefined firewall groups include needed rules, such as core networking rules to allow Trellix applications.

Firewall group

Description

Trellix core networking

Contains the core networking rules provided by Trellix and includes rules to allow Trellix applications and DNS.

Note

You can't change or delete rules in this rule group. If you need to, you can create a duplicate of the group, make changes to the rules, then select the Disable Trellix core networking rules option in the Firewall Options policy to disable the group. But, this might disrupt network communications on the client system.

ePolicy Orchestrator server

Contains rules to allow ePO - On-prem services to run.

Basic networking (Required)

Contains rules to allow basic networking services, such as DNS, to run.

VPN

Contains rules to allow VPN services to run.

ICMP

Contains rules to allow all ICMP traffic.

Windows AD authentication

Contains rules to allow Windows Active Directory authentication.

NetBIOS

Contains rules to allow inbound and outbound NetBIOS services and sessions, and block untrusted NetBIOS services.

Web/FTP

Contains rules to allow outbound HTTPS and FTP services.

Mail clients

Contains rules to allow outbound mail services, such as POP.

Network tools

Contains rules to allow Remote Desktop (RDP) connections.